Executive brief
A vulnerability exists in the audio and video playback component of Mozilla Firefox and Thunderbird. This flaw could allow a malicious website or email to cause the application to crash or behave unexpectedly by providing specially crafted media content. This primarily impacts the reliability and availability of the browser or email client for the user.
Technical details
The vulnerability is classified as an 'Incorrect Boundary Condition' (CWE-754) and 'Use of Out-of-range Pointer Offset' (CWE-823) within the Audio/Video: Playback component of Mozilla browsers and mail clients. An attacker can exploit this by delivering malicious media content over the network, requiring no special privileges or user interaction beyond visiting a site or viewing an email. The primary impact is a high loss of availability (denial-of-service) due to memory safety issues. Patches are available in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and Thunderbird versions 149 and 140.9.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 115.34, < 140.9
- Mozilla Thunderbird < 149, < 140.9
- Red Hat Enterprise Linux 7, 10.0
Timeline
- 2026-03-24: disclosed
- 2026-03-24: advisory
- 2026-03-24: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2018102
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-21/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930