CVE-2026-6784: Memory safety bugs fixed in Firefox 150 and Thunderbird 150
Memory safety bugs present in Firefox 149 and Thunderbird 149. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150 - Upgrade
Upgrade
firefoxto a version that resolves this vulnerability.Fixed in 150 - Upgrade
Upgrade
thunderbirdto a version that resolves this vulnerability.Fixed in 150
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-6746
- CVE-2026-6747
- CVE-2026-6748
- CVE-2026-6749
- CVE-2026-6750
- CVE-2026-6751
- CVE-2026-6752
- CVE-2026-6753
- CVE-2026-6754
- CVE-2026-6755
- CVE-2026-6757
- CVE-2026-6758
- CVE-2026-6759
- CVE-2026-6760
- CVE-2026-6761
- CVE-2026-6762
- CVE-2026-6763
- CVE-2026-6764
- CVE-2026-6765
- CVE-2026-6766
- CVE-2026-6767
- CVE-2026-6768
- CVE-2026-6769
- CVE-2026-6770
- CVE-2026-6771
- CVE-2026-6772
- CVE-2026-6773
- CVE-2026-6774
- CVE-2026-6775
- CVE-2026-6776
- CVE-2026-6777
- CVE-2026-6778
- CVE-2026-6779
- CVE-2026-6780
- CVE-2026-6781
- CVE-2026-6782
- CVE-2026-6783
- CVE-2026-7321
- CVE-2026-8091
- CVE-2026-6784
- CVE-2026-6785
- CVE-2026-6786
- CVE-2026-6756
Frequently Asked Questions
What are the memory safety bugs in CVE-2026-6784?
CVE-2026-6784 describes memory safety bugs in Firefox 149 and Thunderbird 149 that potentially allow exploitation leading to arbitrary code execution.
How can I resolve CVE-2026-6784?
To fix CVE-2026-6784, upgrade to Firefox 150 or Thunderbird 150 to benefit from the applied memory safety fixes.
What is the severity rating of CVE-2026-6784?
CVE-2026-6784 has a severity rating of high, with a CVSS score of 7.5.
What is the potential impact of exploiting CVE-2026-6784?
Exploiting CVE-2026-6784 could lead to memory corruption and potentially allow attackers to execute arbitrary code.
Which products are affected by CVE-2026-6784?
The affected products are Mozilla Firefox and Mozilla Thunderbird, specifically versions prior to 150.