PT-2026-33956 · Mozilla+2 · Thunderbird+3

Published

2026-04-21

·

Updated

2026-06-10

·

CVE-2026-6770

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 150 Firefox ESR versions prior to 140.10 Thunderbird versions prior to 150 Thunderbird versions prior to 140.10 Tor Browser versions prior to 15.0.10
Description An issue in the Storage: IndexedDB component allows websites to track users across different sites, tabs, and windows for the entire duration of the browser process. This persists even in Private Browsing mode, Tor Browser sessions, and after using the "New Identity" reset. The flaw exists because the indexedDB.databases() function returns metadata in a deterministic, unsorted internal bucket order from a global nsTHashSet called StorageDatabaseNameHashtable. By creating multiple controlled databases and reading the permutation order of the response, a stable tracking identifier (fingerprint) can be generated with approximately 44 bits of entropy, uniquely identifying users without their permission.
Recommendations Update Firefox to version 150 or later. Update Firefox ESR to version 140.10 or later. Update Thunderbird to version 150 or 140.10 or later. Update Tor Browser to version 15.0.10 or later.

Fix

DoS

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:10757
ALSA-2026:10766
ALSA-2026:10767
ALSA-2026:12285
ALSA-2026:13537
ALSA-2026:15892
ALSA-2026:19348
BDU:2026-06301
CVE-2026-6770
OESA-2026-2105
OESA-2026-2106
OESA-2026-2107
OESA-2026-2108
OESA-2026-2109
OPENSUSE-SU-2026:10610-1
OPENSUSE-SU-2026:10626-1
RHSA-2026:10757
RHSA-2026:10766
RHSA-2026:10767
RHSA-2026:19348

Affected Products

Firefox
Red Os
Rocky Linux
Thunderbird