cbcvebase.
CVE-2026-2773
published 2026-02-24

CVE-2026-2773: Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148…

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 148, Firefox ESR 115.33, Firefox ESR 140.8, Thunderbird 148, and Thunderbird 140.8.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianfirefox< firefox 148.0-1 (sid)firefox 148.0-1 (sid)
debianfirefox-esr< firefox 148.0-1 (sid)firefox 148.0-1 (sid)
debianthunderbird< firefox 148.0-1 (sid)firefox 148.0-1 (sid)
mozillafirefox< 115.33.0115.33.0
mozillafirefox< 148.0148.0
mozillafirefox
mozillafirefox>= 128.0 < 140.8.0140.8.0
mozillathunderbird< 140.8.0140.8.0
mozillathunderbird< 148.0148.0
mozillathunderbird>= 0 < 1:140.8.0esr-1~deb11u11:140.8.0esr-1~deb11u1
mozillathunderbird>= 0 < 1:140.8.0esr-1~deb12u11:140.8.0esr-1~deb12u1
mozillathunderbird>= 0 < 1:140.8.0esr-1~deb13u11:140.8.0esr-1~deb13u1
mozillathunderbird>= 0 < 1:140.8.0esr-11:140.8.0esr-1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL