CVE-2026-6747: Use-after-free in the WebRTC component
Use-after-free in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-6746
- CVE-2026-6747
- CVE-2026-6748
- CVE-2026-6749
- CVE-2026-6750
- CVE-2026-6751
- CVE-2026-6752
- CVE-2026-6753
- CVE-2026-6754
- CVE-2026-6757
- CVE-2026-6759
- CVE-2026-6761
- CVE-2026-6762
- CVE-2026-6763
- CVE-2026-6764
- CVE-2026-6765
- CVE-2026-6766
- CVE-2026-6767
- CVE-2026-6769
- CVE-2026-6770
- CVE-2026-6771
- CVE-2026-6772
- CVE-2026-6776
- CVE-2026-6785
- CVE-2026-6786
- CVE-2026-6755
- CVE-2026-6758
- CVE-2026-6760
- CVE-2026-6768
- CVE-2026-6773
- CVE-2026-6774
- CVE-2026-6775
- CVE-2026-6777
- CVE-2026-6778
- CVE-2026-6779
- CVE-2026-6780
- CVE-2026-6781
- CVE-2026-6782
- CVE-2026-6783
- CVE-2026-7321
- CVE-2026-8091
- CVE-2026-6784
- CVE-2026-6756
Frequently Asked Questions
What is the severity of CVE-2026-6747?
CVE-2026-6747 has been assessed with high severity due to the potential for exploitation affecting the WebRTC component.
How do I fix CVE-2026-6747?
To fix CVE-2026-6747, update to Firefox version 150, Firefox ESR version 140.10, Thunderbird version 150, or Thunderbird ESR version 140.10.
Which software is affected by CVE-2026-6747?
Affected software for CVE-2026-6747 includes Firefox versions prior to 150, Firefox ESR versions prior to 140.10, Thunderbird versions prior to 150, and Thunderbird ESR versions prior to 140.10.
Can CVE-2026-6747 be exploited remotely?
Yes, CVE-2026-6747 may be exploited remotely, allowing attackers to execute code on affected systems.
What is the nature of the vulnerability CVE-2026-6747?
CVE-2026-6747 is a use-after-free vulnerability in the WebRTC component that can lead to arbitrary code execution.