CVE-2026-7320: Information disclosure due to incorrect boundary conditions in the Audio/Video component
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.35.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.10.1 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 150.0.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.10.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.35.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 150.0.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.10.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-7320?
CVE-2026-7320 is rated as a moderate severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2026-7320?
To fix CVE-2026-7320, users should update to Firefox versions 150.0.1, Firefox ESR 140.10.1, or Firefox ESR 115.35.1.
What does CVE-2026-7320 affect?
CVE-2026-7320 affects Mozilla Firefox versions prior to 150.0.1 and Mozilla Firefox ESR versions prior to 140.10.1 and 115.35.1.
What type of vulnerability is CVE-2026-7320?
CVE-2026-7320 is an information disclosure vulnerability caused by incorrect boundary conditions in the Audio/Video component.
Is there a risk if I do not update for CVE-2026-7320?
Yes, if you do not update for CVE-2026-7320, you are at risk of potential information disclosure that could compromise your privacy.