Junglewise Threat Intelligence

CVE-2026-12319: Mozilla Firefox denial of service in Audio/Video Playback

CVE-2026-12319 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the audio and video playback component of the Firefox web browser could allow a malicious website to cause the browser to crash or become unresponsive. This results in a denial-of-service, disrupting the user's browsing session and potentially leading to the loss of unsaved data in other open tabs. The issue is resolved in Firefox version 152.

Technical details

A denial-of-service (DoS) vulnerability exists in the Audio/Video: Playback component of Mozilla Firefox. While specific root cause details (such as a null pointer dereference or resource exhaustion) are not disclosed in the advisory, the flaw allows a remote attacker to trigger a crash or hang in the browser process via specially crafted media content. The vulnerability is reachable via the network when a user visits a malicious or compromised webpage. This issue was tracked as Bug 2026933 and is fixed in Firefox 152.

Affected products

  • Mozilla Firefox < 152

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory
  • 2026-06-16: patched

References

Related threats