Junglewise Threat Intelligence

CVE-2026-2772: Mozilla Firefox and Thunderbird use-after-free in Audio/Video Playback

CVE-2026-2772 · Severity: critical · CVSS 9.8 · Published 2026-02-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Red Hat, Mozilla.

Executive brief

Mozilla Firefox and Thunderbird are popular web browsers and email clients. A critical vulnerability in the audio and video playback component could allow an attacker to compromise a user's system. If exploited, this could lead to unauthorized access to sensitive data, system instability, or the execution of malicious software.

Technical details

A use-after-free (CWE-416) vulnerability was identified in the Audio/Video: Playback component of Mozilla products. The flaw occurs when the application continues to use a pointer after the memory it points to has been freed, leading to memory corruption. An attacker could potentially exploit this over the network without user interaction (according to the NIST CVSS vector) to achieve remote code execution or a denial-of-service condition. The vulnerability is fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8. Red Hat has also issued advisories for affected Enterprise Linux versions.

Affected products

  • Mozilla Firefox < 148
  • Mozilla Firefox ESR < 115.33, < 140.8
  • Mozilla Thunderbird < 148, < 140.8
  • Red Hat Enterprise Linux Server (v. 7 ELS) 7

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: patched
  • 2026-02-24: advisory

References

Related threats