CVE-2026-6770Patch(mozilla / firefox)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 25 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 19 signals
  • Disclosure: 8 classified signals
  • General: 6 classified signals
  • Peaked 4d ago at 11 mentions (2026-04-27); latest day: 1
  • 25 total mentions across 7 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline25 mentions / 7d
036811Mentions · 2026-04-21: 1Mentions · 2026-04-23: 2Mentions · 2026-04-27: 11Mentions · 2026-04-28: 6Mentions · 2026-04-29: 1Mentions · 2026-04-30: 3Mentions · 2026-05-03: 1Patch / Workaround · 2026-04-21: 1Patch / Workaround · 2026-04-23: 2Patch / Workaround · 2026-04-27: 5Patch / Workaround · 2026-04-28: 5Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 2Patch / Workaround · 2026-05-03: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-23: 1Technical Details · 2026-04-27: 8Technical Details · 2026-04-28: 6Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 204-2104-2304-2704-2804-2904-3005-03
Signal classification3 categories
Patch
1144.0%
Disclosure
832.0%
General
624.0%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-04-211
Patch1
2026-04-232
Patch2
2026-04-2711
Disclosure4General4Patch3
2026-04-286
Disclosure3Patch3
2026-04-291
Patch1
2026-04-303
Disclosure1General1Patch1
2026-05-031
General1
Full discourse20 posts
  • Pirat_Nation 🔴@Pirat_Nation
    Disclosure

    A newly disclosed vulnerability in Firefox (CVE-2026-6770) allowed websites to track users across different sites that lasted for the lifetime of the browser process. This vulnerability let any website quietly build a stable tracking identifier that lasted for the whole lifetime of your Firefox process. It didn’t steal data or abuse storage, it simply read the predictable order in which the IndexedDB API returned database metadata and that order never changed as long as the browser stayed open, so sites could link your activity across tabs, windows, and even after you cleared data or hit the Tor reset button. After the issue was reported Mozilla rolled out the fix in Firefox 150 and ESR 140.10 on April 21 (Tor Browser got the same update). The patch randomizes that metadata order so the trick no longer works.

    Post summary

    The post announces a new tracking vulnerability in Firefox that exploits predictable IndexedDB ordering, and notes that Mozilla has issued a patch to randomize the metadata order to prevent the attack.

    46213122.8K602198.2K
    336.1K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    🚨 Firefox & Tor privacy broken by new bug CVE-2026-6770 allowed websites to track users across sites — even in: • Private Browsing • Tor Browser • “New Identity” sessions No clicks needed. Just visit a site. ⚠ Root issue: IndexedDB leaked a stable fingerprint tied to the browser process Impact: • Cross-site tracking • Tor anonymity weakened ✅ Fixed in: Firefox 150 / Tor 15.0.10 Update immediately. https://securityaffairs.com/191374/security/firefox-bug-cve-2026-6770-enabled-cross-site-tracking-and-tor-fingerprinting.html

    Post summary

    CVE-2026-6770 leaks a stable IndexedDB fingerprint, enabling cross-site tracking even in private browsing, and has been fixed in Firefox 150 and Tor 15.0.10.

    27024141.9K
    16.1K followersView on X
  • Lain on the Blockchain@CryptoCyberia
    Patch

    OH NONONONONONONO >The vulnerability is tracked as CVE-2026-6770 and has been patched This vulnerability allowed Tor operated via Firefox to be tracked through the Onion network. https://t.co/efHdatapDe

    Post summary

    The tweet announces that CVE‑2026‑6770, which enabled tracking of Tor traffic in Firefox, has been patched.

    4103651.5K
    19.3K followersView on X
  • Yousef ِAbdullah - يوسف عبدالله@abnabdullah5
    Patch

    ثغرة CVE-2026-6770 في فايرفوكس وتور سمحت بتتبع المستخدمين عبر المواقع حتى في التصفح الخاص بسبب خلل في IndexedDB. موزيلا أغلقت الثغرة في تحديث فايرفوكس 150 وتور أصدر 15.0.10. لا دلائل على استغلال نشط، لكن الخطر كان في تجاوز آليات العزل وكشف هوية الجلسات. #تقنية #الامن_السيبراني https://t.co/4tvlSs2XL9

    Post summary

    El CVE‑2026‑6770 en Firefox y Tor permitió rastrear usuarios mediante un fallo en IndexedDB, pero no hay evidencia de explotación activa; Mozilla y Tor solucionaron el problema con sus actualizaciones correspondientes.

    01040410
    10.2K followersView on X
  • Grok@grok
    Patch

    Evet, ilginç bir privacy sorunu. CVE-2026-6770, Firefox’un IndexedDB bileşenindeki bir açık sayesinde private browsing ve Tor Browser’da bile siteler arası fingerprinting yapılmasına izin veriyordu (indexedDB.databases() üzerinden stabil bir tanımlayıcı sızdırıyordu). Mozilla 21 Nisan 2026’da Firefox 150, ESR 140.10 ve Tor Browser 15.0.10 ile yamadı. Detaylı advisory: https://www.mozilla.org/en-US/security/advisories/mfsa2026-30/ Hemen güncelle!

    Post summary

    The post highlights CVE‑2026‑6770, a privacy vulnerability in Firefox’s IndexedDB that leaked a stable identifier enabling fingerprinting, and notes that Mozilla patched the issue on April 21 2026 with specific browser releases.

    10030250
    8.7M followersView on X
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌تعرض فايرفوكس لثغرة أمنية في ميزة IndexedDB، والتي يمكن استغلالها لتتبع المستخدمين عبر المواقع الإلكترونية وتحديد هويتهم على شبكة تور. وقد أغلقت موزيلا هذه الثغرة الأمنية، التي تم تعريفها كـ CVE-2026-6770. يُنصح المستخدمون بتحديث المتصفح إلى أحدث إصدار للحماية من هذه الثغرة. 🔗 للمزيد: https://www.security.nl/posting/934354/Firefox-bug+maakt+cross-site+tracking+en+Tor-fingerprinting+mogelijk?channel=rss

    Post summary

    Mozilla discloses CVE‑2026‑6770, a flaw in Firefox’s IndexedDB that enables cross‑site tracking and Tor fingerprinting. The issue has been fixed, so users should update to the latest browser version.

    00030700
    267 followersView on X
  • 🏴‍☠️🏴🇺🇸 Liberty336 🇺🇸🏴🏴‍☠️@Liberty_336
    General

    Need to bypass internet censorship? Liberty336 has re-opened our hidden tor services and made a new tor bridge! For security reasons, use tor browser 15.0.10 or up to avoid CVE-2026-6770! If you ever forget our .onion or public tor bridge information, it's literally at the bottom of the homepage of our website. (Private bridges are distributed via Tor Project BridgeDB + friends) There's also a "copy" button that will copy the public bridge code into your clipboard, simply paste into your tor web browser search panel and boom, it works! We also enabled regular access and tor access to our IRC network. Simply go to: liberty336 .com/irc #main is the main channel. If you're a client who wants to leave a message on IRC without staying online for a long period of time, simply use memoserv to send a memo to whoever is helping you. If you're an IRC enthusiast who likes to join niche networks and support Open Source, Liberty, etc, you're welcome to come join and idle. These services will be very helpful to those who have need for them. (Especially the bridge) Back to backend work, but will have more updates for you in the future.

    Post summary

    The post announces the existence of CVE‑2026‑6770 affecting Tor Browser, recommending an update to mitigate it, without providing exploit details or active exploitation evidence.

    00011104
    1.3K followersView on X
  • Anti-Malware.Ru@Anti_Malware
    Disclosure

    Исследователи обнаружили уязвимость в Firefox, из-за которой сайты могли отслеживать пользователей даже в режиме приватного просмотра. Проблема, получившая идентификатор CVE-2026-6770, также затронула Tor Browser, поскольку он основан на Firefox. https://www.anti-malware.ru/news/2026-04-27-111332/49844

    Post summary

    Обнаружена новая уязвимость в Firefox (CVE‑2026‑6770), которая позволяет сайтам отслеживать пользователей даже в приватном режиме, и эта проблема также затронула Tor Browser. В тексте отсутствуют сведения о PoC, эксплойтах, активных атаках или доступных патчах.

    01010119
    3.3K followersView on X
  • hackplayers@hackplayers
    General

    Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting https://securityaffairs.com/191374/security/firefox-bug-cve-2026-6770-enabled-cross-site-tracking-and-tor-fingerprinting.html

    Post summary

    The article notes that Firefox CVE‑2026‑6770 allows cross‑site tracking and Tor fingerprinting, but it does not provide any proof‑of‑concept, exploit code, active exploitation evidence, or patch information.

    01010455
    54.9K followersView on X
  • Jeff Whitehead@Whitehead4Jeff
    Disclosure

    Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprinting - https://securityaffairs.com/191374/security/firefox-bug-cve-2026-6770-enabled-cross-site-tracking-and-tor-fingerprinting.html

    Post summary

    The article announces that a recent Firefox vulnerability (CVE-2026-6770) permits cross‑site tracking and Tor fingerprinting, but it does not provide exploit code, active use reports, or patch details.

    0001061
    181 followersView on X
  • Ejaj AHmed 🦅@aeejazkhan
    Patch

    🛑A new Firefox flaw, CVE-2026-6770, let websites track users during the full browser session. Any site could create a stable identifier without permission or visible signs. The bug used the predictable order of IndexedDB metadata returned by Firefox. That order stayed the same until the browser process was fully closed. Because of this, sites could link activity across tabs and windows. Tracking could continue even after clearing data or using the Tor reset button. The flaw did not steal files, passwords, or stored data. It only abused metadata order to recognize the same browser session. Mozilla fixed the issue on April 21. The patch arrived in Firefox 150 and ESR 140.10, with Tor Browser updated too. Firefox now randomizes the metadata order. This stops websites from using the trick again.

    Post summary

    Firefox’s CVE‑2026‑6770 allowed sites to track users via predictable IndexedDB metadata order, but Mozilla patched it in Firefox 150/ESR 140.10 by randomizing that metadata.

    00010107
    9.6K followersView on X
  • EFANI Secure Cellphone Service@efani
    Patch

    A Firefox flaw could have let attackers fingerprint Tor users, putting privacy at risk. Update your browsers now to stay protected against threats like CVE-2026-6770. 🛡️ #cybersecurity #privacy Source: Security Week https://t.co/zRaXZ8psEv

    Post summary

    The post alerts to a Firefox flaw (CVE‑2026‑6770) that could allow attackers to fingerprint Tor users and urges readers to update their browsers to mitigate the risk.

    00010256
    9.2K followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs
    General

    #Firefox bug CVE-2026-6770 enabled cross-site tracking and #Tor fingerprinting https://securityaffairs.com/191374/security/firefox-bug-cve-2026-6770-enabled-cross-site-tracking-and-tor-fingerprinting.html #securityaffairs #hacking

    Post summary

    The tweet simply announces that CVE‑2026‑6770 can enable cross‑site tracking and Tor fingerprinting, providing no further technical, patch, or exploit details.

    00010289
    37.6K followersView on X
  • Arif EMRE@arifemre062
    Patch

    Tor Browser routes your traffic through the Tor anonymity network and separates sessions. "New Identity" is the reset button: new Tor circuits, cleared cookies, cleared storage. CVE-2026-6770 (Mozilla Bug 2024220) was fixed in Firefox 150, released April 21, 2026.

    Post summary

    The text announces that CVE‑2026‑6770 was fixed in Firefox 150 released on April 21, 2026, without providing vulnerability or exploitation details.

    1000056
    55 followersView on X
  • HexHunter@HexHunter02
    General

    The vulnerability, tracked as CVE-2026-6770, is related to the IndexedDB browser API, which is used for storing structured data on the client side. https://t.co/KBjcHXW5Hl

    Post summary

    The statement merely announces CVE‑2026‑6770 as related to the IndexedDB browser API, providing no further technical, exploit, or mitigation details.

    0000033
    1 followersView on X
  • Meridian Group@MeridianEU
    Patch

    CVE-2026-6770 in #Firefox allowed cross-site fingerprinting in Private Browsing, enabling unrelated domains to detect a shared unique identifier and link user activity. Patched April 21, 2026 in Firefox 150, ESR 140.10, and Thunderbird. https://t.co/XAf3hwBpN9

    Post summary

    The tweet announces that CVE‑2026‑6770, which allows cross‑site fingerprinting in Firefox’s Private Browsing mode, was patched on April 21, 2026 for Firefox 150, ESR 140.10, and Thunderbird.

    0000046
    57 followersView on X
  • ninp0@ninp0
    Disclosure

    New on 0dayinc: CVE-2026-6770 and the Firefox IndexedDB Cross-Origin Correlation Leak. Our whitepaper breaks down how indexedDB.databases() became a process-lifetime correlation signal in Firefox/Tor, plus fix versions and safe lab validation. https://www.0dayinc.com/post/whitepaper-cve-2026-6770-and-the-firefox-indexeddb-cross-origin-correlation-leak

    Post summary

    A whitepaper has been released detailing CVE‑2026‑6770, explaining how indexedDB.databases() can be used for cross‑origin correlation leaks in Firefox/Tor, and it provides fix versions.

    0000062
    494 followersView on X
  • omvapt@omvapt
    General

    #Firefox #vulnerabilities #bug CVE-2026-6770 enabled #cross_site_tracking and #Tor_fingerprinting https://ift.tt/1wHKYF6 https://t.co/g6KT7L2C66

    Post summary

    The tweet highlights CVE‑2026‑6770 as enabling cross‑site tracking and Tor fingerprinting, but provides no evidence of an active exploit, patch, or proof of concept.

    0000092
    380 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: CVE-2026-6770 lets attackers fingerprint Firefox and Tor users across sessions via IndexedDB, patched in Firefox 150 and Tor Browser 15.0.10 on April 21, 2026. https://threatcluster.io/cluster/firefox-bug-cve-2026-6770-allows-tracking-of-tor-users-628a0545

    Post summary

    CVE-2026-6770 enables attackers to fingerprint Firefox and Tor users via IndexedDB; patches were released in Firefox 150 and Tor Browser 15.0.10.

    0000064
    160 followersView on X
  • Israel@f1tym1
    Disclosure

    InfoSec News Nuggets 04/27/2026 https://ift.tt/6UxosAJ Firefox Vulnerability Allows Tor User Fingerprinting Researchers disclosed CVE-2026-6770, an IndexedDB issue that can let sites correlate a user’s activity across domains, including in Firefox Private Browsing and Tor Br…

    Post summary

    Researchers have revealed CVE‑2026‑6770, an IndexedDB vulnerability in Firefox that lets sites correlate Tor browser users across domains, potentially exposing their activity beyond private browsing. No exploit code or patch is discussed, and no active exploitation is reported.

    0000060
    953 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---

Explore more