Executive brief
Mozilla Firefox is a widely used web browser. A vulnerability in its audio and video processing component could allow a malicious website to cause the browser to crash or potentially perform unauthorized actions. This issue stems from how the browser handles specific data boundaries when playing media content.
Technical details
An integer overflow and incorrect boundary condition vulnerability exists in the Audio/Video component of Mozilla Firefox. The flaw is triggered when the browser processes specially crafted media content, leading to memory safety issues. An attacker can exploit this by hosting a malicious audio or video file on a website; when a user visits the site, the browser's media engine fails to properly validate data boundaries. This can result in a denial-of-service (crash) or potentially be leveraged for more complex memory corruption attacks. The vulnerability is fixed in Firefox 151 and Firefox ESR 140.11.
Affected products
- Mozilla Firefox < 151
- Mozilla Firefox ESR < 140.11
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched
- 2026-05-19: advisory