CVE-2026-6752: Incorrect boundary conditions in the WebRTC component
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.35 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 115.35 - Upgrade
Upgrade
Mozilla Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 140.10
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-6746
- CVE-2026-6749
- CVE-2026-6750
- CVE-2026-6752
- CVE-2026-6754
- CVE-2026-2781
- CVE-2026-6762
- CVE-2026-6767
- CVE-2026-6772
- CVE-2026-6785
- CVE-2026-6747
- CVE-2026-6748
- CVE-2026-6751
- CVE-2026-6753
- CVE-2026-6757
- CVE-2026-6759
- CVE-2026-6761
- CVE-2026-6763
- CVE-2026-6764
- CVE-2026-6765
- CVE-2026-6766
- CVE-2026-6769
- CVE-2026-6770
- CVE-2026-6771
- CVE-2026-6776
- CVE-2026-6786
- CVE-2026-6755
- CVE-2026-6758
- CVE-2026-6760
- CVE-2026-6768
- CVE-2026-6773
- CVE-2026-6774
- CVE-2026-6775
- CVE-2026-6777
- CVE-2026-6778
- CVE-2026-6779
- CVE-2026-6780
- CVE-2026-6781
- CVE-2026-6782
- CVE-2026-6783
- CVE-2026-7321
- CVE-2026-8091
- CVE-2026-6784
- CVE-2026-6756
Frequently Asked Questions
What is the severity of CVE-2026-6752?
The severity of CVE-2026-6752 has not been explicitly categorized, but it involves incorrect boundary conditions in the WebRTC component, which can be critical.
How do I fix CVE-2026-6752?
To fix CVE-2026-6752, update to Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, or Thunderbird 140.10.
Which versions of Mozilla products are affected by CVE-2026-6752?
CVE-2026-6752 affects Mozilla Firefox versions up to 150, and Firefox ESR versions up to 115.35 and 140.10.
What are the potential risks of CVE-2026-6752?
CVE-2026-6752 may lead to security vulnerabilities in WebRTC, potentially causing crashes or exploitation in affected Mozilla products.
Is CVE-2026-6752 a remote code execution vulnerability?
While CVE-2026-6752 involves incorrect boundary conditions, it does not directly indicate a remote code execution vulnerability, but should be treated with caution.