BRIEFING NOTE: CVE-2026-6783 OVERVIEW CVE-2026-6783 is an integer overflow vulnerability affecting the Audio/Video Playback component in Mozilla Firefox and Thunderbird. The flaw stems from incorrect boundary condition handling and was patched in both Firefox 150 and Thunderbird 150. SEVERITY The vulnerability carries a CVSS v3.1 score of 5.3 (MEDIUM), with a network-based attack vector requiring no privileges or user interaction. While the attack complexity is low, the impact is limited to integrity compromise with no confidentiality or availability impact. The FAUCET Risk Score of 41.0/100 indicates moderate concern relative to other vulnerabilities. EXPLOITATION STATUS There is currently no evidence of active exploitation. The vulnerability does not appear on the Known Exploited Vulnerabilities list, and community attention remains minimal. The extremely low EPSS score of 0.0003 suggests minimal likelihood of exploitation in the wild. Organizations should prioritize patching based on their Firefox and Thunderbird deployment footprint rather than imminent threat concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* | ||
< 150.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.