Boundary Condition Vulnerability in Firefox Audio/Video Component
CVE-2026-16359

9.1CRITICAL

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
21 July 2026

What is CVE-2026-16359?

A boundary condition error in the Audio/Video component of Firefox could allow an attacker to exploit the handling of certain input data. This vulnerability affects specific versions of Firefox and can lead to unexpected behavior in the application. Mozilla has released patches in Firefox 153, as well as in Firefox ESR 115.38 and 140.13, to mitigate this issue.

Affected Version(s)

Firefox 115.38

Firefox 140.13

Firefox 153

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jacolon Walker
.