Use-After-Free Vulnerability in Firefox Audio/Video Component
CVE-2026-84120
5.4MEDIUM
What is CVE-2026-84120?
A use-after-free vulnerability has been identified in the audio/video component of Firefox, which could lead to potential exploitation if not addressed. This issue allows an attacker to utilize memory that has already been freed, potentially leading to arbitrary code execution or crashes. Mozilla has released updates to mitigate this risk, specifically in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2. Users are strongly advised to update to these versions to ensure their systems remain secure.
Affected Version(s)
Firefox 115.40
Firefox 140.15
Firefox 153.2