Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.
The bug consists of undefined behavior in the module responsible for handling audio and video content. Undefined behavior means that the code performs operations whose consequences are not specified by the language or platform specification, which may lead to consequences that are predictable or controllable by an attacker. An attacker can potentially trigger this bug through specially crafted multimedia content delivered remotely, without requiring user interaction or possessing privileges.
An attacker can gain unauthorized access to sensitive data processed by the application (high loss of confidentiality) and cause data or process memory modification (high loss of integrity). The attack is possible remotely, without authentication and without user interaction.
Mozilla Firefox must be urgently updated to version 149 or later and Mozilla Thunderbird to version 149 or later. Details of patches are available in the vendor's security advisories: mfsa2026-20 (Firefox) and mfsa2026-23 (Thunderbird).
Mozilla Firefox in versions prior to 149 and Mozilla Thunderbird in versions prior to 149.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMozilla Firefox
APPMozilla< 149.0Mozilla Thunderbird
APPMozilla< 149.0
Related vulnerabilities
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ...