CVE-2026-6756
published 2026-04-21CVE-2026-6756: Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.24%
15.2th percentile
Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 149 on Android (Nessus ID 310634)
vuldb·2026-04-28
CVE-2026-6756 [LOW] Mozilla Firefox up to 149 on Android (Nessus ID 310634)
A vulnerability classified as problematic was found in Mozilla Firefox up to 149 on Android. Affected is an unknown function. Executing a manipulation can lead to an unknown weakness.
This vulnerability is handled as CVE-2026-6756. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-v4x8-424m-xfg7: Mitigation bypass in Firefox for Android
ghsa_unreviewed·2026-04-21
CVE-2026-6756 [HIGH] CWE-200 GHSA-v4x8-424m-xfg7: Mitigation bypass in Firefox for Android
Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
Red Hat
firefox: Mitigation bypass in Firefox for Android
vendor_redhat·2026-04-21·CVSS 6.1
CVE-2026-6756 [MEDIUM] CWE-807 firefox: Mitigation bypass in Firefox for Android
firefox: Mitigation bypass in Firefox for Android
Mitigation bypass in Firefox for Android. This vulnerability was fixed in Firefox 150.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Mitigation bypass in Firefox for Android
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: firefox (Red Hat Enterprise Linux 9) - Not affected
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6756
vendor_mozilla
CVE-2026-6756 Mozilla Foundation Security Advisory 2026-30: CVE-2026-6756
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6756
Product: Firefox
Impact: high
Fixed in: Firefox 150
No detection rules found.
No public exploits indexed.
2026-04-21
Published