CVE-2026-4724 describes a critical undefined behavior vulnerability found in the Audio/Video component of Mozilla Firefox and Thunderbird, affecting versions prior to 149. This vulnerability carries a CVSS score of 9.1, indicating it is network-exploitable with low attack complexity and no user interaction, potentially leading to high confidentiality and integrity impacts. Despite its severity, there is currently no evidence of active exploitation, public exploit code availability, or significant community discussion, and it is not listed in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.