CVE-2026-7320

7.5

Mozilla · Firefox, Thunderbird

An information disclosure vulnerability exists in the Audio/Video component of Mozilla Firefox and Thunderbird due to incorrect boundary conditions.

Executive summary

A high-severity information disclosure vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to potentially access sensitive memory data.

Vulnerability

The flaw is an information disclosure vulnerability stemming from incorrect boundary condition handling within the Audio/Video component. The CVSS vector of AV:N/AC:L/PR:N indicates that the vulnerability is exploitable by an unauthenticated remote attacker without requiring user interaction.

Business impact

The vulnerability poses a significant risk to data confidentiality, as it allows attackers to read sensitive information processed by the browser or mail client. Given the CVSS score of 7.5, this is categorized as a high-severity issue that could lead to unauthorized access to private user data, potentially compromising credentials or session information stored in memory.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to the fixed versions (150.0.1 or the corresponding ESR releases) as specified in the Mozilla security advisories.

Proactive Monitoring: Monitor network traffic for unusual patterns related to media processing and review system logs for anomalies in browser or email client behavior.

Compensating Controls: While no direct compensating control prevents this specific memory-level flaw, users should employ standard browser security practices, such as disabling unnecessary media auto-play features, to reduce the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by this vulnerability is substantial due to the ease with which an unauthenticated remote actor could potentially exfiltrate sensitive memory contents. Organizations must prioritize the deployment of the Mozilla patches across all endpoints to ensure comprehensive protection against this information disclosure risk.

More Mozilla CVEs

Sources

Originally found and disclosed by Xuehao Guo, per the CVE Program record.