Description
Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
Published: 2026-05-07
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the audio and video playback component has incorrect boundary checks, which can allow the parser to read beyond the intended buffer when processing malformed media files. Although the update does not explicitly mention a crash or data leak, such over‑read can lead to a memory corruption event that may cause the application to crash or expose unexpected data.

Affected Systems

The vulnerability affects all releases of Mozilla Firefox and Thunderbird that use the legacy audio/video playback component before the patch was applied in the ESR branches and the newer releases. Specifically, any Firefox or Thunderbird version older than Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, or Firefox ESR 115.35.2 is susceptible. Users should verify that their build precedes those fixed versions and apply the corresponding update.

Risk and Exploitability

The EPSS score is not available and the issue is not listed in CISA’s KEV catalog, so the current exploitation probability is unknown. No CVSS score is provided, but memory corruption in a browser component is generally considered a high‑risk class vulnerability. Based on the description, it is inferred that the likely attack vector is delivering a malformed media file via a webpage or malicious download, potentially triggering a crash or data leak. The risk is elevated for environments that routinely encounter untrusted media content, and timely remediation is advised.

Generated by OpenCVE AI on May 7, 2026 at 19:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox ESR 140.10.1 or later on the 140 branch, or ESR 115.35.2 or later on the 115 branch, which incorporate the playback fix.
  • If the ESR branch cannot be updated, migrate to a newer non‑ESR Firefox release that has the updated playback logic.
  • Until a patch is available, restrict or disable playback of media files from untrusted or unknown sources using browser security settings or group policy controls.
  • Consider disabling the legacy audio/video playback engine entirely in environments that do not require media playback.

Generated by OpenCVE AI on May 7, 2026 at 19:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 07 May 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-126
CWE-787

Thu, 07 May 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-127

Thu, 07 May 2026 16:30:00 +0000

Type Values Removed Values Added
References

Thu, 07 May 2026 16:15:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Firefox ESR 115.35.2. Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, Thunderbird 140.10.1, and Firefox ESR 115.35.2.
Weaknesses CWE-119
CWE-127
References

Thu, 07 May 2026 15:30:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 140.10.2 and Firefox ESR 115.35.2. Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Firefox ESR 115.35.2.
References

Thu, 07 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Thu, 07 May 2026 13:00:00 +0000

Type Values Removed Values Added
Description Incorrect boundary conditions in the Audio/Video: Playback component. This vulnerability was fixed in Firefox ESR 140.10.2 and Firefox ESR 115.35.2.
Title Incorrect boundary conditions in the Audio/Video: Playback component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-07T15:22:39.614Z

Reserved: 2026-05-07T12:45:05.120Z

Link: CVE-2026-8091

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-07T13:16:14.087

Modified: 2026-05-07T16:16:23.700

Link: CVE-2026-8091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T20:00:12Z

Weaknesses