CVE-2026-6782
published 2026-04-21CVE-2026-6782: Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.25%
16.7th percentile
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150 | Firefox 150 |
| mozilla | firefox | < 150.0 | 150.0 |
| mozilla | thunderbird | < Thunderbird 150 | Thunderbird 150 |
| mozilla | thunderbird | < 150.0 | 150.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Firefox: Firefox: Information disclosure in the IP Protection component
vendor_redhat·2026-04-21·CVSS 7.5
CVE-2026-6782 [HIGH] CWE-201 Firefox: Firefox: Information disclosure in the IP Protection component
Firefox: Firefox: Information disclosure in the IP Protection component
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
A flaw was found in the IP Protection component of Firefox. This vulnerability allows for information disclosure, which could lead to the exposure of sensitive data. The specific method of exploitation is not detailed in the available information.
Mozilla
Mozilla Foundation Security Advisory 2026-33: CVE-2026-6782
vendor_mozilla·CVSS 7.5
CVE-2026-6782 [HIGH] Mozilla Foundation Security Advisory 2026-33: CVE-2026-6782
Mozilla Foundation Security Advisory 2026-33
CVE: CVE-2026-6782
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 150
Mozilla
Mozilla Foundation Security Advisory 2026-30: CVE-2026-6782
vendor_mozilla·CVSS 7.5
CVE-2026-6782 [HIGH] Mozilla Foundation Security Advisory 2026-30: CVE-2026-6782
Mozilla Foundation Security Advisory 2026-30
CVE: CVE-2026-6782
Product: Firefox
Impact: high
Fixed in: Firefox 150
VulDB
Mozilla Firefox up to 149 IP Protection information disclosure (Nessus ID 310637)
vuldb·2026-04-28·CVSS 7.5
CVE-2026-6782 [HIGH] Mozilla Firefox up to 149 IP Protection information disclosure (Nessus ID 310637)
A vulnerability categorized as problematic has been discovered in Mozilla Firefox up to 149. The impacted element is an unknown function of the component IP Protection. The manipulation results in information disclosure.
This vulnerability is cataloged as CVE-2026-6782. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
GHSA
GHSA-rm28-r39x-h3x2: Information disclosure in the IP Protection component
ghsa_unreviewed·2026-04-21
CVE-2026-6782 [HIGH] CWE-200 GHSA-rm28-r39x-h3x2: Information disclosure in the IP Protection component
Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 150.
No detection rules found.
No public exploits indexed.
2026-04-21
Published