Description
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The updated description confirms a use‑after‑free flaw in the Audio/Video component of Mozilla Firefox and Thunderbird. The flaw allows an attacker to access freed memory, potentially enabling arbitrary code execution. If exploited, the attacker could gain full control of the affected system, compromising confidentiality, integrity, and availability. The weakness is identified as a memory corruption issue, which falls into the common weakness category of use‑after‑free.

Affected Systems

The affected products are Mozilla Firefox and Mozilla Thunderbird. In Firefox, versions prior to 155, or earlier than ESR 115.40, 140.15, or 153.2, are vulnerable. In Thunderbird, versions prior to 155, or earlier than ESR 140.15 or 153.2, are also vulnerable. Users running these earlier releases should upgrade to the patched versions to mitigate the issue.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 5.4, reflecting medium severity. The likely attack vector is the delivery of malicious audio or video content, which an attacker can trigger through a web page or local media file. Without a patch, exploitation remains possible and could lead to arbitrary code execution.

Generated by OpenCVE AI on September 2, 2026 at 04:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to at least version 155, or to the latest ESR release (115.40 or newer) to apply the official fix.
  • Upgrade Thunderbird to at least version 155, or to the latest ESR release (140.15 or newer) to apply the official fix.
  • If an immediate upgrade is not feasible, disable the Audio/Video component or restrict its execution through policy or configuration to block malicious media.
  • Implement monitoring for attempt handling of media content and configure the browser to reject suspicious audio/video streams until a patch is applied.

Generated by OpenCVE AI on September 2, 2026 at 04:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4770-1 firefox-esr security update
Debian DLA Debian DLA DLA-4775-1 thunderbird security update
Debian DSA Debian DSA DSA-6481-1 firefox-esr security update
Debian DSA Debian DSA DSA-6483-1 thunderbird security update
History

Wed, 02 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 02 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox
References

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Use-after-free in the Audio/Video component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T21:44:08.380Z

Reserved: 2026-09-01T07:25:08.573Z

Link: CVE-2026-84120

cve-icon Vulnrichment

Updated: 2026-09-01T13:46:49.943Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-01T13:20:05.817

Modified: 2026-09-02T16:41:18.357

Link: CVE-2026-84120

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-01T12:18:40Z

Links: CVE-2026-84120 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:30:04Z

Weaknesses