Executive brief
A vulnerability exists in the Audio/Video component of Mozilla Firefox and Thunderbird, which are widely used web browsers and email clients. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored in the application's memory. This could lead to the exposure of private user data or browsing history, potentially compromising user privacy and corporate confidentiality.
Technical details
An information disclosure vulnerability exists in Mozilla Firefox and Thunderbird's Audio/Video component due to incorrect boundary conditions, specifically an out-of-bounds read (CWE-125). The flaw is triggered when the application fails to properly validate the bounds of a memory buffer during the processing of audio or video content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or view specially crafted media content, allowing the attacker to read sensitive information from the process memory. While Thunderbird is affected, the risk is lower in email contexts where scripting is disabled, but remains significant in browser-like contexts. Patches are available in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, and Thunderbird 150.0.1/140.10.1.
Affected products
- Mozilla Firefox < 150.0.1
- Mozilla Firefox ESR < 140.10.1, < 115.35.1
- Mozilla Thunderbird < 150.0.1, < 140.10.1
- Red Hat Enterprise Linux 7, 8, 10
Timeline
- 2026-04-28: disclosed: Initial advisory published by Mozilla.
- 2026-04-28: patched: Fixed in Firefox 150.0.1 and ESR versions.
- 2026-04-30: patched: Fixed in Thunderbird 150.0.1 and 140.10.1.
- 2026-05-19: advisory: Red Hat published security updates for RHEL.
References
- https://bugzilla.mozilla.org/show_bug.cgi?id=2027433
- https://www.mozilla.org/security/advisories/mfsa2026-35/
- https://www.mozilla.org/security/advisories/mfsa2026-36/
- https://www.mozilla.org/security/advisories/mfsa2026-37/
- https://www.mozilla.org/security/advisories/mfsa2026-38/
- https://www.mozilla.org/security/advisories/mfsa2026-39/
- https://access.redhat.com/errata/RHSA-2026:19153