Executive brief
A vulnerability in the audio and video playback component of the Firefox web browser could allow a malicious website to cause the browser to crash or become unresponsive. This results in a denial-of-service, disrupting the user's browsing session and potentially leading to the loss of unsaved data in other open tabs. The issue is resolved in Firefox version 152.
Technical details
A denial-of-service (DoS) vulnerability exists in the Audio/Video: Playback component of Mozilla Firefox. While specific root cause details (such as a null pointer dereference or resource exhaustion) are not disclosed in the advisory, the flaw allows a remote attacker to trigger a crash or hang in the browser process via specially crafted media content. The vulnerability is reachable via the network when a user visits a malicious or compromised webpage. This issue was tracked as Bug 2026933 and is fixed in Firefox 152.
Affected products
- Mozilla Firefox < 152
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched