Junglewise Threat Intelligence

CVE-2026-16359: Mozilla Firefox incorrect boundary conditions in Audio/Video GMP

CVE-2026-16359 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the Gecko Media Plugin (GMP) component of the Firefox web browser, which handles audio and video content. An attacker could potentially exploit this flaw to cause memory-related issues when the browser processes specially crafted media files. This could lead to browser instability or unauthorized access to information, impacting the privacy and reliability of the user's browsing session.

Technical details

A vulnerability classified as 'incorrect boundary conditions' exists within the Audio/Video: Gecko Media Plugin (GMP) component of Mozilla Firefox. The flaw is triggered during the processing of media content, where the component fails to properly validate memory boundaries. While specific exploitation details are restricted in the associated Bugzilla report (Bug 2045424), such boundary condition errors typically lead to buffer overflows or out-of-bounds reads/writes. An attacker could exploit this by enticing a user to visit a malicious website or play a crafted media file, potentially resulting in a process crash or arbitrary code execution within the context of the GMP sandbox. The issue is resolved in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 115.38, < 140.13

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched
  • 2026-07-21: advisory

References

Related threats