Executive brief
Mozilla Firefox and Thunderbird are popular web browsing and email applications. A security vulnerability in their audio and video processing component could allow a malicious website or email to cause the application to crash or behave unexpectedly. This could lead to a denial of service, interrupting user operations and potentially requiring a restart of the software.
Technical details
A vulnerability exists in the Audio/Video: Web Codecs component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions (CWE-754). This flaw results in an out-of-bounds write (CWE-787) when processing specifically crafted media content. An attacker can exploit this over the network without any special privileges or user interaction beyond visiting a malicious site or viewing a malicious email. The primary impact is a high-severity denial of service (application crash), though memory corruption vulnerabilities of this class can sometimes be leveraged for further exploitation. The issue is resolved in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Affected products
- Mozilla Firefox < 149
- Mozilla Firefox ESR < 140.9
- Mozilla Thunderbird < 149
- Mozilla Thunderbird ESR < 140.9
Timeline
- 2026-03-24: disclosed
- 2026-03-24: patched
- 2026-03-24: advisory
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2020422
- https://www.mozilla.org/security/advisories/mfsa2026-20/
- https://www.mozilla.org/security/advisories/mfsa2026-22/
- https://www.mozilla.org/security/advisories/mfsa2026-23/
- https://www.mozilla.org/security/advisories/mfsa2026-24/
- https://access.redhat.com/errata/RHSA-2026:5930
- https://access.redhat.com/errata/RHSA-2026:5931