Description
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Published: 2026-09-01
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a use-after-free flaw in the Audio/Video component of Mozilla Firefox. The flaw allows an attacker to access freed memory, potentially enabling arbitrary code execution. If exploited, the attacker could gain full control of the affected system, compromising confidentiality, integrity, and availability. The weakness is identified as a memory corruption issue, which falls into the common weakness category of use-after-free.

Affected Systems

The affected product is Mozilla Firefox. Versions prior to Firefox 155, Firefox ESR 115.40, ESR 140.15, and ESR 153.2 are vulnerable and have the issue fixed in the releases mentioned. Users running these earlier versions are at risk.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is not disclosed, but use-after-free vulnerabilities typically have a high severity rating. The likely attack vector is the delivery of malicious audio or video content, which an attacker can trigger through a web page or local media file. Without a patch, exploitation remains possible and could lead to arbitrary code execution.

Generated by OpenCVE AI on September 1, 2026 at 13:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to at least version 155, or to the latest ESR release (115.40 or newer) to apply the official fix.
  • If an immediate upgrade is not feasible, disable the Audio/Video component or restrict its execution through policy or configuration to block malicious media.
  • Implement monitoring for attempt handling of media content and configure the browser to reject suspicious audio/video streams until a patch is applied.

Generated by OpenCVE AI on September 1, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Use-after-free in the Audio/Video component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T13:47:04.126Z

Reserved: 2026-09-01T07:25:08.573Z

Link: CVE-2026-84120

cve-icon Vulnrichment

Updated: 2026-09-01T13:46:49.943Z

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:05.817

Modified: 2026-09-01T14:17:48.573

Link: CVE-2026-84120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T13:30:17Z

Weaknesses