Description
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Published: 2026-05-19
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises from an invalid pointer dereference in the Audio/Video Web Codecs component. When the system processes media data that causes this dereference, the component crashes, leading to a temporary halt of media playback or browser instability. The vulnerability corresponds to CWE-476, CWE-416, and CWE-400. The primary impact is loss of availability, which can be disruptive for end users and critical services relying on uninterrupted media functionality.

Affected Systems

Mozilla Firefox versions prior to 151 and the ESR release prior to 140.11 are affected. The vulnerability is tied to the Web Codecs API within Firefox’s audio and video subsystem.

Risk and Exploitability

The CVSS score for this vulnerability is 7.5; EPSS is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is the delivery of crafted media data via a malicious web page or application that leverages the Web Codecs API. An attacker would need to force the browser to process such data to trigger the crash; no publicly available exploitation tools are known for this defect.

Generated by OpenCVE AI on May 19, 2026 at 17:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Mozilla Firefox update (≥151 or ESR 140.11).
  • If immediate patching is not possible, disable the Web Codecs feature via about:config settings or policy files to prevent the vulnerable component from executing.
  • Maintain an active patch management schedule by regularly checking Mozilla security advisories for updates related to browser media functionality.

Generated by OpenCVE AI on May 19, 2026 at 17:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 19 May 2026 17:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11. Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
References

Tue, 19 May 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-476

Tue, 19 May 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 May 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-416
CWE-476
Vendors & Products Mozilla
Mozilla firefox

Tue, 19 May 2026 13:45:00 +0000

Type Values Removed Values Added
Description Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
Title Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-19T17:10:51.600Z

Reserved: 2026-05-19T12:30:13.364Z

Link: CVE-2026-8968

cve-icon Vulnrichment

Updated: 2026-05-19T14:24:19.884Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-19T14:16:53.277

Modified: 2026-05-19T15:16:35.187

Link: CVE-2026-8968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T17:15:10Z

Weaknesses