CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-6748

Critical · CVSS 9.8

Firefox / Thunderbird Web Codecs — Uninitialized memory read/use (CWE-457, CWE-824) in Audio/Video Web Codecs component

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-457, CWE-824

Description

Uninitialized memory in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 150, Firefox ESR 140.10, Thunderbird 150, and Thunderbird 140.10.

Search profile — drives PoC discovery

Symbols WebCodecsAudioDecoderVideoDecoderAudioEncoderVideoEncoderuninitialized memorymozallocMediaDataEncodedAudioChunkEncodedVideoChunkImageBitmapVideoFrameAudioData
Keywords CVE-2026-6748Firefox 150Firefox ESR 140.10Thunderbird 150Thunderbird 140.10Web Codecs uninitialized memoryMozilla MFSA2026-30MFSA2026-32MFSA2026-33MFSA2026-34bugzilla 2022604CWE-457CWE-824proof of conceptPoC
Versions: Firefox < 150, Firefox ESR < 140.10, Thunderbird < 150, Thunderbird < 140.10

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T18:30:14.000Z