CVE-2026-4697 is a high-severity vulnerability (CVSS 7.5) stemming from incorrect boundary conditions in the Audio/Video: Web Codecs component, affecting Firefox < 149, Firefox ESR < 140.9, and Thunderbird < 149/140.9. This flaw has a network attack vector and low attack complexity, allowing a remote attacker to achieve a high availability impact, potentially leading to a denial of service. There is currently no evidence of active exploitation, and no public exploit code is available in common repositories like Metasploit or ExploitDB. While community discussion and media coverage are minimal, vendors have released security updates to mitigate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 140.9.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* | ||
< 149.0CPE matchmatch criteria | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.