CVE-2026-6765 is an information disclosure vulnerability in the Form Autofill component affecting Mozilla Firefox and Mozilla Thunderbird. The issue allows unintended exposure of information through the browser or mail client's autofill functionality. Publicly available detail identifies the affected component and the fixed versions, but does not provide sufficient technical specificity about the vulnerable code path or triggering conditions to reliably characterize the underlying flaw beyond information disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone proof-of-concept for CVE-2026-6765 affecting Mozilla Firefox Form Autofill. It contains two files: a README describing the vulnerability, impact, and affected handlers, and a single executable PoC script in JavaScript. The exploit is not part of a larger framework. The main exploit logic is in poc.js. It is designed to be pasted into the Firefox Browser Console on a vulnerable build. The script accesses the current browser window global via gBrowser.selectedBrowser.browsingContext.currentWindowGlobal, retrieves the FormAutofill actor with getActor("FormAutofill"), and then sends privileged receiveMessage calls to exposed test-only handlers. Primary capabilities demonstrated by the PoC are: (1) exfiltration of all saved credit card and address records using FormAutofill:GetRecords, (2) persistence/injection of attacker-controlled autofill data using FormAutofill:SaveAddress, and (3) destructive deletion of stored payment cards using FormAutofill:RemoveCreditCards after collecting GUIDs from returned records. The README also notes a fourth exposed handler, FormAutofill:SaveCreditCard, though it is not invoked in the PoC. There are no external network callbacks, hardcoded IPs, or C2 endpoints in the code. The meaningful fingerprintable targets are internal Firefox actor/message endpoints and the Mozilla module FormAutofillParent.sys.mjs. Overall, this is an operational browser-context exploit PoC showing confidentiality, integrity, and availability impact against saved autofill/payment data on affected Firefox versions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
13 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.