CVE-2026-6779 is an unspecified issue in the JavaScript Engine component affecting Mozilla Firefox and Thunderbird, both patched in version 150. The vulnerability allows attackers to gain limited information disclosure through network-based attacks without requiring user interaction or special privileges. With a CVSS score of 5.3 (Medium severity), the attack has low complexity and results in partial confidentiality impact, though integrity and availability remain unaffected. This vulnerability is not listed in the Known Exploited Vulnerabilities catalog and shows minimal community attention, with an EPSS score of 0.0006 indicating very low real-world exploitation probability. Organizations should apply the Firefox 150 and Thunderbird 150 updates as part of standard patch management, though this does not appear to be an actively exploited threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.