ZeroHour

CVE-2026-92043

mass

Out-of-Bounds Memory Flaw Enables Privilege Escalation in Firefox Audio/Video Component

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-92043 is a privilege escalation vulnerability in Mozilla Firefox caused by incorrect boundary conditions (a memory/buffer out-of-bounds flaw, CWE-120) in the browser's Audio/Video component. Exploitation occurs over the network with low attack complexity but requires user interaction, meaning a victim most plausibly needs to visit a malicious page or open crafted media content for the attacker to trigger the out-of-bounds access. A successful exploit gives the attacker high impact on confidentiality, integrity, and availability of the victim's browser context, effectively escaping normal content-process restrictions and enabling code execution with elevated privileges. All users of Firefox releases prior to Firefox 156 and Firefox ESR releases prior to ESR 153.3 are affected. No public proof-of-concept exists and the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, so exploitation status is currently unknown/none known.

What to do: Update desktop and mobile Firefox installations to Firefox 156, and update enterprise-managed deployments to Firefox ESR 153.3 (or move pinned ESR fleets to that version) as soon as possible. Because exploitation requires user interaction, defenders should verify browser auto-update is enabled and warn users against untrusted media content in the interim. No other workaround substitutes for patching, since the flaw sits in core media-handling code.

Affected
Mozilla Firefoxversions before Firefox 156
Mozilla Firefox ESR (Extended Support Release)versions before Firefox ESR 153.3
Estimated exposure
mass≈100–200 million Firefox users worldwide (order of magnitude: 10^8) — Firefox maintains roughly 2–3% of the global browser market across ~4–5 billion internet users, and because this is a client-side browser flaw affecting the default (non-ESR) channel, essentially the entire user base that has not yet…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.

Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.