Executive brief
Firefox and Thunderbird contain a vulnerability in their Audio/Video processing component that can be exploited to cause a denial-of-service condition, rendering the affected application unresponsive or crash. An attacker could trigger this issue by crafting malicious media content, potentially disrupting user productivity and availability of these widely-used communication and browsing applications.
Technical details
CVE-2026-92063 is a denial-of-service vulnerability in the Audio/Video component of Firefox and Thunderbird. The vulnerability allows an attacker to craft malicious audio or video content that, when processed by the vulnerable component, triggers an application crash or hang. The attack vector is network-based and requires user interaction (e.g., opening a malicious media file or visiting a webpage containing embedded media). The vulnerability was patched in Firefox 156 and Thunderbird 156. No evidence of active exploitation in the wild has been reported.
Affected products
- Mozilla Firefox before 156
- Mozilla Thunderbird before 156
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in Firefox 156 and Thunderbird 156