CVE-2026-4695

7.5

Mozilla · Firefox, Thunderbird

A vulnerability in the Mozilla Web Codecs component involving incorrect boundary conditions allows for potential denial of service via unauthenticated network-based attacks.

Executive summary

A critical boundary condition vulnerability in Mozilla Firefox and Thunderbird exposes users to potential service disruption through unauthenticated remote exploitation.

Vulnerability

This flaw exists within the Audio/Video Web Codecs component, where incorrect boundary checks can be triggered by an unauthenticated attacker. The vulnerability is characterized by a high impact on system availability, allowing for potential crashes or hangs.

Business impact

The exploitation of this vulnerability results in a denial of service, which can significantly disrupt business operations and user productivity. Given the CVSS score of 7.5, this high severity flaw poses a substantial risk to organizational continuity. Unauthenticated attackers can trigger this remotely, making it a priority for organizations relying on these browsers for daily workflows.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 149 or, if utilizing the Extended Support Release, to version 140.9.

Proactive Monitoring: Monitor endpoint logs for abnormal browser application crashes or frequent service restarts that may indicate attempted exploitation.

Compensating Controls: Ensure that browser-based security policies are enforced and consider deploying network-level traffic inspection to block suspicious multimedia streams that may target the Web Codecs component.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high severity of this vulnerability, combined with the ease of remote exploitation, necessitates immediate patching across all environments. IT administrators should prioritize the deployment of the provided updates to Firefox and Thunderbird to prevent potential service instability and maintain the security posture of the organization.

More Mozilla CVEs

Sources

Originally found and disclosed by Atte Kettunen, per the CVE Program record.