Executive brief
A use-after-free vulnerability exists in Firefox's audio and video playback engine that could allow an attacker to crash the browser or potentially execute arbitrary code. The flaw affects Firefox and Thunderbird across multiple versions and was addressed in recent security updates released September 1, 2026.
Technical details
A use-after-free memory corruption vulnerability exists in Mozilla Firefox's Audio/Video component (CVE-2026-84120, reported by Ukyo Akai). The vulnerability occurs when memory is accessed after it has been freed, potentially allowing arbitrary code execution or denial of service. The issue is triggered through normal web browsing and does not require special privileges or user interaction beyond visiting a malicious webpage. Patches were released in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, and corresponding Thunderbird versions (155, 140.15, and 153.2) on September 1, 2026.
Affected products
- Mozilla Firefox below 155
- Mozilla Firefox ESR 115.x below 115.40, 140.x below 140.15, 153.x below 153.2
- Mozilla Thunderbird below 155, 140.x below 140.15, 153.x below 153.2
Timeline
- 2026-09-01: disclosed: Publicly disclosed by Mozilla in MFSA2026-82
- 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 115.40/140.15/153.2, Thunderbird 155/140.15/153.2