Description
Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a site isolation issue that affects the Audio/Video: Web Codecs component. Site isolation is used by browsers to keep data and resources from one web origin separate from those of another. The CVE notes the issue but does not describe the specific data that could be accessed or how the isolation is broken, so the exact scope of the impact cannot be determined from the available information.

Affected Systems

Mozilla Firefox, including the Extended Support Release, and Mozilla Thunderbird, including the Extended Support Release, are affected. The bug was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird ESR 153.1, meaning any earlier releases are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. The EPSS score of < 1 % suggests that exploits are unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Because the CVE does not detail an exploit path, the most likely attack vector is inferred to be a malicious website that a user visits or a compromised extension that can trigger the Web Codecs API. This inference is based on typical site isolation weaknesses rather than explicit evidence in the description.

Generated by OpenCVE AI on August 21, 2026 at 20:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox or Thunderbird to the official fix versions, namely Firefox 154 or later and Firefox ESR 153.1 or newer, or Thunderbird 154 or later and Thunderbird ESR 153.1 or newer, which remove the site isolation weakness.
  • If an upgrade cannot be applied immediately, disable the Web Codecs API in the browser (e.g., via the about:config setting hidden.disable.webcodecs or by enforcing a policy that blocks the API) to eliminate the attack surface.
  • Enable automatic updates or establish a patch management process that ensures the latest Firefox and Thunderbird releases are deployed as soon as they become available.

Generated by OpenCVE AI on August 21, 2026 at 20:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Fri, 21 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Fri, 21 Aug 2026 00:15:00 +0000


Thu, 20 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-285

Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1. Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 154 and Firefox ESR 153.1.
Title Site isolation issue in the Audio/Video: Web Codecs component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-20T17:21:48.093Z

Reserved: 2026-08-17T11:59:08.402Z

Link: CVE-2026-74981

cve-icon Vulnrichment

Updated: 2026-08-20T15:33:57.828Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T13:17:37.040

Modified: 2026-08-25T16:11:37.900

Link: CVE-2026-74981

cve-icon Redhat

Severity : Low

Publid Date: 2026-08-18T12:23:40Z

Links: CVE-2026-74981 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:30:07Z

Weaknesses