Description
Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Published: 2026-04-21
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Potential leakage of sensitive data (information disclosure)
Action: Apply Patch
AI Analysis

Impact

This vulnerability arises from the use of uninitialized memory within the Audio/Video: Web Codecs component of Firefox. The flaw allows the software to read memory that has not been properly initialized, potentially exposing remnants of previously processed data. If an attacker can craft input to the Web Codecs API, they may be able to trigger a read of these memory areas, resulting in the disclosure of confidential information or a system crash, thereby creating a denial‑of‑service scenario. The weakness is a classic case of accessing memory without proper initialization (CWE‑788).

Affected Systems

Mozilla Firefox users running versions prior to Firefox 150 or Firefox ESR 140.10 are affected by this flaw. The issue has been addressed in Firefox 150 and the ESR 140.10 release, so any deployment of these or later builds is considered safe. Systems that rely on the Web Codecs API for media processing are the primary targets for this vulnerability.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that broad exploitation has not been observed or documented. Without a widely available exploit or significant public reconnaissance, the risk of immediate compromise is low to moderate. However, the impact of data leakage or a crash could be serious depending on the context of media processing workloads. The absence of a CVSS score in the public data suggests that the severity assessment is incomplete, but the nature of the flaw warrants precautionary action. The likely attack vector involves malicious media content or a crafted Web page that utilizes the Web Codecs API to read uninitialized memory.

Generated by OpenCVE AI on April 22, 2026 at 03:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 150 or later, or to Firefox ESR 140.10 or later, to incorporate the bug fix.
  • If an update is not immediately feasible, disable the Web Codecs API by setting the about:config preference "media.webrtc.enable-unsafe-codecs" to false or by using a browser extension that restricts access to untrusted media codecs.
  • Limit use of the Web Codecs API to trusted contexts and monitor for media processing errors, ensuring that untrusted or malformed media content is blocked.

Generated by OpenCVE AI on April 22, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Apr 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-788

Wed, 22 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
Description Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150 and Firefox ESR 140.10. Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.
Weaknesses CWE-457
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Apr 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Description Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150 and Firefox ESR 140.10.
Title Uninitialized memory in the Audio/Video: Web Codecs component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-21T23:34:39.302Z

Reserved: 2026-04-21T12:40:45.603Z

Link: CVE-2026-6748

cve-icon Vulnrichment

Updated: 2026-04-21T18:39:23.825Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-04-21T13:16:20.910

Modified: 2026-04-22T00:16:30.200

Link: CVE-2026-6748

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T03:30:06Z

Weaknesses