CVE-2026-4724

CWE-758CWE-4759 documents8 sources
Severity
9.1CRITICAL
EPSS
0.0%
top 96.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 24

Description

Undefined behavior in the Audio/Video component. This vulnerability affects Firefox < 149 and Thunderbird < 149.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

CVEListV5mozilla/firefoxunspecified149
NVDmozilla/firefox< 149.0
CVEListV5mozilla/thunderbirdunspecified149
NVDmozilla/thunderbird< 149.0

🔴Vulnerability Details

3
GHSA
GHSA-j97q-98f4-5wq3: Undefined behavior in the Audio/Video component2026-03-24
CVEList
Undefined behavior in the Audio/Video component2026-03-24
OSV
CVE-2026-4724: Undefined behavior in the Audio/Video component2026-03-24

📋Vendor Advisories

4
Red Hat
firefox: Undefined behavior in the Audio/Video component2026-03-24
Debian
CVE-2026-4724: firefox - Undefined behavior in the Audio/Video component. This vulnerability affects Fire...2026
Mozilla
Mozilla Foundation Security Advisory 2026-23: CVE-2026-4724
Mozilla
Mozilla Foundation Security Advisory 2026-20: CVE-2026-4724

🕵️Threat Intelligence

1
Wiz
CVE-2026-4724 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-4724 (CRITICAL CVSS 9.1) | Undefined behavior in the Audio/Vid | cvebase.io