Junglewise Threat Intelligence

CVE-2026-84122: Mozilla Firefox use-after-free in Audio/Video component

CVE-2026-84122 · Severity: medium · CVSS 5.4 · Published 2026-09-01

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox is a widely-used web browser that processes audio and video content as users browse websites. A use-after-free vulnerability in the Audio/Video component could allow an attacker to execute arbitrary code or crash the browser when a user visits a malicious website or interacts with crafted multimedia content. This could lead to data theft, session hijacking, or temporary loss of browser functionality.

Technical details

CVE-2026-84122 is a use-after-free memory safety vulnerability in Mozilla Firefox's Audio/Video component. The vulnerability occurs when memory is accessed after it has been freed, potentially allowing an attacker to corrupt memory state or execute arbitrary code. The attack vector is network-based; exploitation requires user interaction such as visiting a malicious webpage or viewing crafted multimedia content. The vulnerability was patched in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2. No active exploitation in the wild has been reported.

Affected products

  • Mozilla Firefox before 155
  • Mozilla Firefox ESR 140.x before 140.15, 153.x before 153.2
  • Mozilla Thunderbird 140.x before 140.15, 153.x before 153.2, before 155

Timeline

  • 2026-09-01: disclosed: Announced as part of Mozilla Foundation Security Advisory 2026-82
  • 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2

References

Related threats