CVE-2026-4697

7.5

Mozilla · Firefox, Thunderbird

A boundary condition error in the Web Codecs component of Mozilla Firefox and Thunderbird allows for potential denial of service via unauthenticated remote exploitation.

Executive summary

Mozilla Firefox and Thunderbird contain a critical boundary condition vulnerability in their Web Codecs component that could lead to application instability or denial of service.

Vulnerability

The vulnerability involves incorrect boundary conditions within the Audio/Video Web Codecs component. This flaw is exploitable by an unauthenticated remote attacker who can trigger the issue through crafted media content.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation could result in a denial of service, causing significant disruption to business operations and user productivity by crashing the browser or email client. Because the flaw is remotely exploitable without authentication, the potential for widespread impact across an organization is considerable.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 149 or later, or to the 140.9 ESR release, as specified in the official vendor security advisories.

Proactive Monitoring: Monitor system logs for recurring application crashes or unexpected service termination events associated with Firefox or Thunderbird processes.

Compensating Controls: Ensure that enterprise security policies restrict the execution of untrusted media files and utilize endpoint protection solutions to identify and block malicious web content.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the prevalence of Firefox and Thunderbird in enterprise environments, this vulnerability poses a significant risk of service disruption. Administrators should prioritize the deployment of the provided patches across all workstations and servers. Failure to update may leave systems vulnerable to denial of service attacks that could impede critical business communications and web-based workflows.

More Mozilla CVEs

Sources

Originally found and disclosed by Lorenzo, per the CVE Program record.