Description
Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
In plain language
AI Act nowThis can let someone crash Firefox or Thunderbird before version 156, or ESR 140.16 or 153.3; affected businesses should update promptly.
A network-reachable use-after-free in the Audio/Video: Web Codecs component permits unauthenticated remote denial of service through crafted content.
What to do now
- Check the version and release channel of Firefox and Thunderbird installed on company computers.
- Update standard releases to 156, or update the applicable ESR branch to 140.16 or 153.3.
- If updates must wait, disable or restrict access to the Web Codecs feature where your managed configuration permits it, then schedule the update.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-92005 and every CVE in our database. Create a free account — no credit card required.
Create Free Account