Input validation error in Mozilla products - CVE-2026-16350
Published: July 21, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: cubeb component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.