Vulnerability intelligence
CVE-2026-6770
Other issue in the Storage: IndexedDB component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
CVSS Score
6.5
Medium
EPSS — Exploit Probability
4.9%
Riskier than 91% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
2 articles across 2 outlets · first covered Apr 27, 2026 · latest Apr 27, 2026
Coverage timeline
-
Firefox bug CVE-2026-6770 enabled cross-site tracking and Tor fingerprintingsecurityaffairs.com · Apr 27, 2026
-
CVE-2026-6770 lets sites track Firefox, Tor users via IndexedDBwww.securityweek.com · Apr 27, 2026