Junglewise Threat Intelligence

CVE-2026-8091: Mozilla Firefox and Thunderbird incorrect boundary conditions in Audio/Video Playback

CVE-2026-8091 · Severity: critical · CVSS 9.8 · Published 2026-05-07

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla, Red Hat.

Executive brief

Mozilla Firefox and Thunderbird are popular web browsing and email applications. A critical vulnerability has been identified in the component responsible for playing audio and video content. If exploited, this could allow an attacker to compromise the application, potentially leading to unauthorized access to data or the ability to execute malicious code on the user's system. Users should update to the latest versions immediately to protect their systems.

Technical details

A vulnerability exists in the Audio/Video: Playback component of Mozilla products due to incorrect boundary conditions (CWE-754/CWE-805). The flaw allows for potential buffer access with an incorrect length value when processing media content. An unauthenticated attacker can exploit this over the network by providing specially crafted audio or video content. While Thunderbird is less susceptible in standard email-reading mode due to disabled scripting, the risk remains in browser-like contexts. The issue has been addressed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.

Affected products

  • Mozilla Firefox < 150
  • Mozilla Thunderbird < 150
  • Mozilla Firefox ESR < 140.10.1, < 115.35.2
  • Mozilla Thunderbird ESR < 140.10.1
  • Red Hat Enterprise Linux 6, 7, 8, 9, 10

Timeline

  • 2026-04-21: advisory: Mozilla Foundation Security Advisory published
  • 2026-05-07: disclosed: NVD publication date

References

Related threats