Junglewise Threat Intelligence

CVE-2026-92005: Mozilla Firefox use-after-free in Audio/Video Web Codecs

CVE-2026-92005 · Severity: medium · CVSS 5.3 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a use-after-free vulnerability in the audio and video codec processing component. An attacker can exploit this flaw by crafting malicious audio or video content that, when processed by the browser or email client, could lead to memory corruption and potential code execution. This affects users viewing untrusted media content in their browsers or email messages.

Technical details

The vulnerability is a use-after-free memory error in the Audio/Video: Web Codecs component of Firefox and Thunderbird. A use-after-free occurs when the application attempts to access memory that has already been freed, allowing an attacker to overwrite freed memory and potentially execute arbitrary code. The vulnerability is triggered when processing audio or video content through web codecs. No special privileges or local access are required; the attack vector is through network delivery of malicious media. Patches are available in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 140.x before 140.16, 153.x before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird 140.x before 140.16, 153.x before 153.3

Timeline

  • 2026-09-15: disclosed: Published by Mozilla Security Advisory 2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, Thunderbird 153.3

References

Related threats