Input validation error in Mozilla Firefox and Firefox for Android - CVE-2026-6781
Published: April 21, 2026
Vulnerability identifier: #VU126694
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-6781
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due an unspecified error in the Audio/Video: Playback component. A remote attacker can trick the victim into visiting a specially crafted web page and crash the browser.
Affected software
Mozilla Firefox
Firefox for Android
Anolis OS
Mozilla Thunderbird
firefox
Firefox for Android
Anolis OS
Mozilla Thunderbird
firefox
How to mitigate CVE-2026-6781
Install updates from vendor's website.
Mozilla Firefox - update to 150.0
Firefox for Android - update to 150.0
Mozilla Thunderbird - update to 150.0
firefox - update to 140.10.0-1
Firefox for Android - update to 150.0
Mozilla Thunderbird - update to 150.0
firefox - update to 140.10.0-1