CVE-2026-8972
Description
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Privilege escalation in Firefox and Thunderbird's WebRTC Audio/Video component, fixed in versions 151.
Vulnerability
CVE-2026-8972 is a privilege escalation vulnerability in the WebRTC Audio/Video component of Firefox and Thunderbird. The flaw exists in the handling of audio/video streams and can be triggered by a crafted web page or content. Affected versions include Firefox prior to 151 and Thunderbird prior to 151 [1][2].
Exploitation
An attacker would need to convince a user to visit a malicious web page or open a crafted email in a browser-like context (scripting is disabled in Thunderbird's email reading, but browser-like contexts are possible). The attacker can exploit the vulnerability to escalate privileges within the browser or Thunderbird process.
Impact
Successful exploitation allows an attacker to escalate privileges, potentially gaining higher-level access to system resources or sensitive data. The CVSS score is 8.8 (High), indicating significant impact on confidentiality, integrity, and availability.
Mitigation
The vulnerability is fixed in Firefox 151 and Thunderbird 151, released on May 19, 2026 [1][2]. Users should update to these versions or later. No workarounds are mentioned; updating is the recommended mitigation.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Range: <151
- Range: <151
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.mozilla.org/security/advisories/mfsa2026-46/nvdVendor Advisory
- www.mozilla.org/security/advisories/mfsa2026-50/nvdVendor Advisory
- bugzilla.mozilla.org/show_bug.cginvdPermissions Required
News mentions
0No linked articles in our index yet.