CVE-2026-4714

7.5

Mozilla · Firefox, Thunderbird

Incorrect boundary conditions in the Audio/Video component of Mozilla Firefox and Thunderbird may lead to a denial of service.

Executive summary

A critical boundary condition vulnerability in the Audio/Video component of Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to cause a denial of service.

Vulnerability

This vulnerability involves incorrect boundary conditions within the Audio/Video processing logic. The flaw is remotely exploitable by an unauthenticated attacker, requiring no user interaction to trigger a crash or service disruption.

Business impact

Successful exploitation of this vulnerability results in a denial of service, rendering the affected browser or email client unresponsive. Given the CVSS score of 7.5, the impact is significant for organizational continuity, as it can disrupt workflows dependent on these applications and potentially lead to service instability.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to version 149 or the corresponding ESR versions (140.9) immediately to implement the required boundary condition fixes.

Proactive Monitoring: Review system logs and application crash reports for recurring anomalies in the Audio/Video processing subsystem.

Compensating Controls: While no direct virtual patch exists, maintain updated endpoint security software to detect abnormal process behavior associated with the browser or email client.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This vulnerability presents a clear risk to operational stability through potential service disruption. IT administrators should prioritize the deployment of the patches provided by Mozilla across all enterprise endpoints. Prompt application of these updates is the only effective way to neutralize the risk of exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Sajeeb Lohani, per the CVE Program record.