CVE-2026-8968
Description
Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An invalid pointer in the Audio/Video: Web Codecs component of Firefox and Thunderbird allows a remote attacker to cause a denial-of-service via crafted media.
Vulnerability
CVE-2026-8968 is a denial-of-service vulnerability in the Audio/Video: Web Codecs component of Firefox, Firefox ESR, and Thunderbird. The flaw is caused by an invalid pointer dereference when processing crafted media content. Affected versions include Firefox before 151, Firefox ESR before 140.11, Thunderbird before 151, and Thunderbird before 140.11 [1][2][3][4].
Exploitation
An attacker must deliver a specially crafted media file or stream to the victim, either through a web page (in Firefox or Thunderbird in browser-like contexts) or via an embedded media element. No special network position or authentication is required beyond the ability to serve content that triggers the vulnerable code path. User interaction is minimal—the victim only needs to load the malicious content [1][2].
Impact
Successful exploitation results in a denial-of-service condition, likely producing a browser crash or application hang. The adversary gains no code execution or data access; the impact is limited to availability degradation. The CVSS v3 base score is 7.5 (High) reflecting the ease of causing service interruption [1][2].
Mitigation
Mozilla released fixes in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11 on May 19, 2026. Users should update to these versions or later. There is no known workaround; applying the security update is the only mitigation [1][2][3][4].
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: <140.11
- Range: <140.11
- Range: <151
- Range: <151
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- www.mozilla.org/security/advisories/mfsa2026-46/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-48/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-50/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-51/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.