CVE-2026-6757
Received Received - Intake
Invalid Pointer Vulnerability in Firefox WebAssembly Component

Publication date: 2026-04-21

Last updated on: 2026-04-22

Assigner: Mozilla Corporation

Description
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-04-21
Last Modified
2026-04-22
Generated
2026-05-07
AI Q&A
2026-04-21
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
mozilla firefox to 150.0 (exc)
mozilla firefox to 140.10.0 (exc)
mozilla thunderbird From 140.0 (inc) to 140.10.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-824 The product accesses or uses a pointer that has not been initialized.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves an invalid pointer in the JavaScript WebAssembly component of Mozilla Firefox. It means that there is a flaw in how the browser handles pointers within WebAssembly code, which could potentially lead to unexpected behavior or security issues. The vulnerability was addressed and fixed in Firefox version 150 and Firefox ESR 140.10.


How can this vulnerability impact me? :

Exploitation of this vulnerability could lead to security risks such as crashes, memory corruption, or potentially arbitrary code execution when processing WebAssembly content in the browser. This could compromise the security and stability of the affected Firefox browser versions before the fix.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update Firefox to version 150 or later, or Firefox ESR to version 140.10 or later, where the issue has been fixed.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart