Junglewise Threat Intelligence

CVE-2026-7320: Mozilla Firefox and Thunderbird out-of-bounds read in Audio/Video component

CVE-2026-7320 · Severity: high · CVSS 7.5 · Published 2026-04-28

Technologies: Mozilla Thunderbird, Red Hat Enterprise Linux, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

A vulnerability exists in the Audio/Video component of Mozilla Firefox and Thunderbird, which are widely used web browsers and email clients. An attacker could exploit this flaw to gain unauthorized access to sensitive information stored in the application's memory. This could lead to the exposure of private user data or browsing history, potentially compromising user privacy and corporate confidentiality.

Technical details

An information disclosure vulnerability exists in Mozilla Firefox and Thunderbird's Audio/Video component due to incorrect boundary conditions, specifically an out-of-bounds read (CWE-125). The flaw is triggered when the application fails to properly validate the bounds of a memory buffer during the processing of audio or video content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or view specially crafted media content, allowing the attacker to read sensitive information from the process memory. While Thunderbird is affected, the risk is lower in email contexts where scripting is disabled, but remains significant in browser-like contexts. Patches are available in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, and Thunderbird 150.0.1/140.10.1.

Affected products

  • Mozilla Firefox < 150.0.1
  • Mozilla Firefox ESR < 140.10.1, < 115.35.1
  • Mozilla Thunderbird < 150.0.1, < 140.10.1
  • Red Hat Enterprise Linux 7, 8, 10

Timeline

  • 2026-04-28: disclosed: Initial advisory published by Mozilla.
  • 2026-04-28: patched: Fixed in Firefox 150.0.1 and ESR versions.
  • 2026-04-30: patched: Fixed in Thunderbird 150.0.1 and 140.10.1.
  • 2026-05-19: advisory: Red Hat published security updates for RHEL.

References

Related threats