Junglewise Threat Intelligence

CVE-2026-8968: Mozilla Firefox denial of service in Web Codecs

CVE-2026-8968 · Severity: info · CVSS 4.3 · Published 2026-05-19

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability in the Firefox web browser could allow a malicious website to crash the application. This occurs when the browser processes specific audio or video content using its Web Codecs component. While this issue primarily affects the reliability of the browser by causing it to stop responding, it does not appear to lead to data theft or unauthorized system access.

Technical details

A denial-of-service (DoS) vulnerability exists in Mozilla Firefox and Firefox ESR within the Audio/Video: Web Codecs component. The flaw is caused by an invalid pointer dereference during the processing of media content. An attacker could exploit this by enticing a user to visit a specially crafted website, leading to a browser crash. The vulnerability is addressed in Firefox 151 and Firefox ESR 140.11. While the impact is limited to availability (DoS), it represents a memory safety issue within the media handling pipeline.

Affected products

  • Mozilla Firefox < 151
  • Mozilla Firefox ESR < 140.11

Timeline

  • 2026-05-19: disclosed
  • 2026-05-19: patched
  • 2026-05-19: advisory

References

Related threats