Executive brief
A vulnerability exists in the Web Codecs component of Mozilla Firefox and Thunderbird, which are widely used web browsers and email clients. This flaw involves the use of uninitialized memory, which could allow an attacker to potentially access sensitive information or cause the application to crash. While Thunderbird is affected, the risk is lower during normal email reading because scripting is disabled by default, though risks remain in browser-like contexts.
Technical details
The vulnerability is classified as a use of uninitialized memory (CWE-457) or uninitialized pointer (CWE-824) within the Audio/Video: Web Codecs component of Mozilla's core engine. An attacker could potentially exploit this over the network without prior authentication or user interaction to achieve a limited impact on confidentiality, integrity, and availability. In Thunderbird, the attack surface is mitigated during standard email viewing as scripting is disabled, but the vulnerability remains reachable in browser-like contexts. Patches have been released in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Affected products
- Mozilla Firefox < 150
- Mozilla Firefox ESR < 140.10
- Mozilla Thunderbird < 150
- Mozilla Thunderbird ESR < 140.10
- Red Hat Enterprise Linux Server (v. 7 ELS) 7
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory
- 2026-04-21: patched
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2025883
- https://www.mozilla.org/security/advisories/mfsa2026-30/
- https://www.mozilla.org/security/advisories/mfsa2026-32/
- https://www.mozilla.org/security/advisories/mfsa2026-33/
- https://www.mozilla.org/security/advisories/mfsa2026-34/
- https://access.redhat.com/errata/RHSA-2026:10757
- https://access.redhat.com/errata/RHSA-2026:10766