Description
Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Published: 2026-09-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption
Action: Patch Immediately
AI Analysis

Impact

A Use‑After‑Free (CWE-416) flaw involving improper memory management (CWE-825) resides in the Audio/Video: Web Codecs component of Mozilla Firefox and Thunderbird. The bug enables a freed object to be accessed again, potentially corrupting memory. While the current data do not confirm arbitrary code execution, the memory corruption could trigger application crashes or compromise the confidentiality, integrity, or availability of the browser process.

Affected Systems

Mozilla Firefox builds older than version 156 and any ESR releases older than 140.16 or 153.3 are vulnerable. The same applies to Mozilla Thunderbird: all products before version 156 and any ESR releases before 140.16 or 153.3 contain the flaw. The vulnerability is fixed in Firefox 156, ESR 140.16, 153.3 and in Thunderbird 156, ESR 140.16, 153.3.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious or compromised web page that invokes the Web Codecs API, meaning the client must run the vulnerable browser version. Successful exploitation could lead to memory corruption within the browser process, potentially affecting availability and data integrity.

Generated by OpenCVE AI on September 20, 2026 at 18:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Mozilla Firefox to version 156 or later, or to any ESR release 140.16 or 153.3.
  • Update Mozilla Thunderbird to version 156 or later, or to any ESR release 140.16 or 153.3.
  • If an update cannot be applied, disable the Web Codecs API by setting the preference media.webcodecs.enabled to false or via group policy.

Generated by OpenCVE AI on September 20, 2026 at 18:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4781-1 firefox-esr security update
Debian DLA Debian DLA DLA-4782-1 thunderbird security update
Debian DSA Debian DSA DSA-6501-1 firefox-esr security update
Debian DSA Debian DSA DSA-6503-1 thunderbird security update
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16. Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, and Thunderbird 140.16. Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 140.16.
References

Tue, 15 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, and Firefox ESR 153.3. Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, and Thunderbird 140.16.
References

Tue, 15 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, and Firefox ESR 153.3.
Title Use-after-free in the Audio/Video: Web Codecs component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-17T20:36:00.514Z

Reserved: 2026-09-15T12:33:23.954Z

Link: CVE-2026-92005

cve-icon Vulnrichment

Updated: 2026-09-17T20:34:22.991Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:16:48.110

Modified: 2026-09-17T21:17:53.067

Link: CVE-2026-92005

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T12:33:24Z

Links: CVE-2026-92005 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:30:03Z

Weaknesses