CRITICAL🇵🇱 Wersja polska

CVE-2026-4724

CVSS 9.1v3.1pub. 2026-03-24upd. 2026-04-13

Undefined behavior in the Audio/Video component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

🤖 AI Analysis
How it works

The bug consists of undefined behavior in the module responsible for handling audio and video content. Undefined behavior means that the code performs operations whose consequences are not specified by the language or platform specification, which may lead to consequences that are predictable or controllable by an attacker. An attacker can potentially trigger this bug through specially crafted multimedia content delivered remotely, without requiring user interaction or possessing privileges.

Impact

An attacker can gain unauthorized access to sensitive data processed by the application (high loss of confidentiality) and cause data or process memory modification (high loss of integrity). The attack is possible remotely, without authentication and without user interaction.

Mitigation & patch

Mozilla Firefox must be urgently updated to version 149 or later and Mozilla Thunderbird to version 149 or later. Details of patches are available in the vendor's security advisories: mfsa2026-20 (Firefox) and mfsa2026-23 (Thunderbird).

Who is affected

Mozilla Firefox in versions prior to 149 and Mozilla Thunderbird in versions prior to 149.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Mozilla Firefox

    APP
    Mozilla
    < 149.0
  • Mozilla Thunderbird

    APP
    Mozilla
    < 149.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product

Use-after-free w Animation timelines Firefox/Thunderbird — RCE

CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product

Use-after-free w WebGPU IPC framework Mozilla — sandbox escape

CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product

Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open

CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product

RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended

CVE-2026-74936CRITICAL9.8same product

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ...