CVE-2026-4709

7.5

Mozilla · Firefox, Thunderbird

A boundary condition error in the Audio/Video GMP component of Mozilla Firefox and Thunderbird may lead to a denial of service.

Executive summary

A critical boundary condition vulnerability in the Mozilla Audio/Video GMP component allows unauthenticated remote attackers to trigger a denial of service condition.

Vulnerability

This vulnerability involves incorrect boundary conditions within the Audio/Video Generic Media Plugin (GMP) component. The flaw is exploitable by an unauthenticated attacker, as indicated by the CVSS attack vector (AV:N/PR:N/UI:N).

Business impact

With a CVSS score of 7.5, this vulnerability represents a high-severity risk to operational continuity. Successful exploitation can lead to a denial of service, rendering browsers or email clients unresponsive and causing significant disruption to user productivity and business workflows.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to the identified fixed versions (149, 115.34, or 140.9 depending on the release channel) immediately.

Proactive Monitoring: Monitor system logs for unexpected application crashes or service restarts associated with media processing threads.

Compensating Controls: Ensure that automated update mechanisms are enabled for all end-user workstations to expedite the deployment of security patches.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The potential for a denial of service against widely deployed software like Firefox and Thunderbird necessitates prompt action. IT administrators should prioritize the deployment of the provided security updates across all managed endpoints to neutralize this risk and maintain system stability.

More Mozilla CVEs

Sources

Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.