CVE-2026-7320Sensitive Information Exposure in Mozilla Firefox

7 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.0%
top 91.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 28

Description

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, and Firefox ESR 115.35.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Mozillamozilla/firefox< Firefox 150.0.1
Mozillamozilla/firefox_esr< Firefox ESR 115.35.1+1
Mozillamozilla/thunderbird< Thunderbird 150.0.1+1

🔴Vulnerability Details

1
VulDB
Mozilla Firefox up to 150.0.0 Video information disclosure2026-04-28

📋Vendor Advisories

5
Mozilla
Mozilla Foundation Security Advisory 2026-38: CVE-2026-7320
Mozilla
Mozilla Foundation Security Advisory 2026-37: CVE-2026-7320
Mozilla
Mozilla Foundation Security Advisory 2026-35: CVE-2026-7320
Mozilla
Mozilla Foundation Security Advisory 2026-36: CVE-2026-7320
Mozilla
Mozilla Foundation Security Advisory 2026-39: CVE-2026-7320
CVE-2026-7320 — Sensitive Information Exposure | cvebase