CVE-2026-6775
published 2026-04-21CVE-2026-6775: Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
PriorityP425medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
0.21%
11.1th percentile
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 149 WebRTC memory corruption (Nessus ID 310638)
vuldb·2026-04-28·CVSS 5.3
CVE-2026-6775 [MEDIUM] Mozilla Firefox up to 149 WebRTC memory corruption (Nessus ID 310638)
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 149. This vulnerability affects unknown code of the component WebRTC. This manipulation causes memory corruption.
This vulnerability is handled as CVE-2026-6775. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-wpg5-vr6r-jrcr: Incorrect boundary conditions in the WebRTC component
ghsa_unreviewed·2026-04-21
CVE-2026-6775 [MEDIUM] CWE-119 GHSA-wpg5-vr6r-jrcr: Incorrect boundary conditions in the WebRTC component
Incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 150.
Red Hat
WebRTC: Firefox: WebRTC: System disruption and unauthorized control via incorrect boundary conditions
vendor_redhat·2026-04-21·CVSS 5.3
CVE-2026-6775 [MEDIUM] CWE-787 WebRTC: Firefox: WebRTC: System disruption and unauthorized control via incorrect boundary conditions
WebRTC: Firefox: WebRTC: System disruption and unauthorized control via incorrect boundary conditions
A flaw was found in the WebRTC component. This vulnerability, caused by incorrect boundary conditions, could lead to memory corruption. An attacker might exploit this to disrupt the affected system or potentially gain unauthorized control.
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6775
vendor_mozilla·CVSS 5.3
CVE-2026-6775 [MEDIUM] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6775
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6775
Product: Firefox
Impact: high
Fixed in: Firefox 150
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6775
vendor_mozilla·CVSS 5.3
CVE-2026-6775 [MEDIUM] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6775
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6775
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
No detection rules found.
No public exploits indexed.
2026-04-21
Published