Description
Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free condition exists within the audio/video processing module of Mozilla Firefox. If triggered, an attacker could potentially execute arbitrary code, hijack execution flow, or cause a denial of service by exploiting corrupted memory. The vulnerability is a classic example of a memory management flaw that undermines process integrity and could lead to privilege escalation if not mitigated. The likely attack vector includes malicious media content or a crafted audio stream delivered through a website, library, or file that the browser processes.

Affected Systems

Vulnerable instances are found in Mozilla Firefox versions prior to 155, as well as legacy ESR releases before 140.15 and 153.2. Users running any of these builds are at risk until they apply the referenced fixes. Modern releases beyond the mentioned thresholds are not affected.

Risk and Exploitability

Because the vulnerability involves a fundamental memory corruption bug, the severity is high. No CVSS score or EPSS figure is available in the current advisory, and the vulnerability is not yet listed in the CISA KEV catalog; however, the absence of these metrics does not reduce the potential impact. Attackers can likely trigger the flaw via crafted audio/video data, making it readily exploitable in a browser context. Given the historical pattern of use‑after‑free bugs, a real‑world exploitation is plausible if the vulnerability remains unpatched.

Generated by OpenCVE AI on September 1, 2026 at 14:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox 155 or later (or ESR 140.15/ESR 153.2) to apply the fix.
  • Enable or enforce automatic updates or a patch‑management process to keep the browser current.
  • Restrict or filter media content from unknown sources by configuring a content‑security policy or using media‑blocking extensions to reduce attack surface until the patch is applied.

Generated by OpenCVE AI on September 1, 2026 at 14:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Use-after-free in the Audio/Video component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T12:18:49.637Z

Reserved: 2026-09-01T07:25:13.250Z

Link: CVE-2026-84122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:06.040

Modified: 2026-09-01T13:20:06.040

Link: CVE-2026-84122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T13:30:16Z

Weaknesses

No weakness.