CVE-2026-92043
massOut-of-Bounds Memory Flaw Enables Privilege Escalation in Firefox Audio/Video Component
CVE-2026-92043 is a privilege escalation vulnerability in Mozilla Firefox caused by incorrect boundary conditions (a memory/buffer out-of-bounds flaw, CWE-120) in the browser's Audio/Video component. Exploitation occurs over the network with low attack complexity but requires user interaction, meaning a victim most plausibly needs to visit a malicious page or open crafted media content for the attacker to trigger the out-of-bounds access. A successful exploit gives the attacker high impact on confidentiality, integrity, and availability of the victim's browser context, effectively escaping normal content-process restrictions and enabling code execution with elevated privileges. All users of Firefox releases prior to Firefox 156 and Firefox ESR releases prior to ESR 153.3 are affected. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently unknown/none known.
What to do: Update desktop and mobile Firefox installations to Firefox 156, and update enterprise-managed deployments to Firefox ESR 153.3 (or move pinned ESR fleets to that version) as soon as possible. Because exploitation requires user interaction, defenders should verify browser auto-update is enabled and warn users against untrusted media content in the interim. No other workaround substitutes for patching, since the flaw sits in core media-handling code.
| Mozilla Firefox | versions before Firefox 156 |
| Mozilla Firefox ESR (Extended Support Release) | versions before Firefox ESR 153.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
- Weakness
- CWE-120
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.