Junglewise Threat Intelligence

CVE-2026-8946: Mozilla Firefox incorrect boundary conditions in Web Codecs

CVE-2026-8946 · Severity: info · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the Firefox web browser's component responsible for processing audio and video content. An attacker could potentially exploit this flaw to cause a browser crash or execute unauthorized code by tricking a user into visiting a malicious website. This could lead to the compromise of user data or the installation of malware on the affected system.

Technical details

A vulnerability classified as 'Incorrect Boundary Conditions' exists within the Audio/Video: Web Codecs component of Mozilla Firefox. The flaw is triggered when the browser processes specially crafted media content via the Web Codecs API. While specific root cause details are restricted in the associated bug report, boundary condition errors typically involve buffer overflows or out-of-bounds access. An attacker can exploit this by hosting a malicious webpage that, when visited, triggers the memory corruption. This could result in a denial-of-service (browser crash) or potentially arbitrary code execution within the context of the browser process. The issue is resolved in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 115.36, < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched
  • 2026-05-19: advisory

References

Related threats