Stanislav Fort[verified]@stanislavfortDisclosure
The tweet announces a high‑severity heap overflow (CVE‑2026‑2757) in Firefox’s WebRTC H.264 decoder, noting the vulnerability type and that Firefox 148 patches it.
ThreatCluster[verified]@threatclusterPatch
Mozilla Firefox ESR 140.8.0 for SUSE and openSUSE includes a patch for CVE-2026-2757 and CVE-2026-2760, addressing sandbox escape in WebRTC and Graphics components.
Joshua Rogers@MegaManSecDisclosure
A new heap overflow vulnerability (CVE-2026-2757) in Firefox's WebRTC H.264 component has been disclosed, but no PoC, exploit, or patch details are provided.
CVE@CVEnewDisclosure
A new CVE (CVE-2026-2757) affecting Firefox versions due to incorrect boundary conditions in WebRTC's audio/video component has been disclosed, with affected version ranges specified.
CERT-PY@CERTpyDisclosure
Three new CVEs (CVE-2026-2759, CVE-2026-2758, CVE-2026-2757) affecting Mozilla products are announced, with links provided for more information.
CRAC Learning - Tech@cracbotDisclosure
The post announces CVE-2026-2757, a critical WebRTC boundary condition flaw affecting Firefox versions below 148, with CVSS 9.8, but provides no PoC, exploit, or patch details.
Infoflowcloud@infoflowcloudDisclosure
The post announces CVE‑2026‑2757, a boundary‑condition flaw in Firefox’s WebRTC audio/video component, affecting versions below 148 and certain ESR releases.
CRAC Learning - Tech@cracbotDisclosure
The post shares basic information about CVE‑2026‑2757, its severity rating, affected Firefox versions, and a link to the NVD entry, but does not include PoC, exploit details, or patch information.