CVE-2026-6762 PUBLISHED

Spoofing issue in the DOM: Core & HTML component

Assigner: mozilla
Reserved: 21.04.2026 Published: 21.04.2026 Updated: 21.04.2026

Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 150, Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Product Status

Vendor Mozilla
Product Firefox
Versions
  • unaffected from 115.35 to 115.* (incl.)
  • unaffected from 140.10 to 140.* (incl.)
  • unaffected from 150 to * (incl.)
Vendor Mozilla
Product Thunderbird
Versions
  • unaffected from 140.10 to 140.* (incl.)
  • unaffected from 150 to * (incl.)

Credits

  • Farras Givari

References