Impact
CVE-2026-92043 is a buffer over-read followed by an out-of-bounds write in the Audio/Video component, which is a privilege escalation flaw (CWE-120, CWE-787). Based on the description, it is inferred that an attacker can supply crafted audio or video content, or embed special elements in a web page, to trigger the overflow and execute code with the process's privileges, potentially compromising confidentiality, integrity, and availability.
Affected Systems
Mozilla Firefox versions before 156 and before Firefox ESR 153.3, and Mozilla Thunderbird versions before 156 and before Thunderbird ESR 153.3, are vulnerable to this privilege escalation flaw.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, and the EPSS score of <1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is delivering crafted media content, typically via a malicious website or user‑opened file, which requires remote user interaction to trigger. While no widespread exploitation has been reported, the high impact warrants immediate mitigation.
OpenCVE Enrichment