CVE-2026-7320Patch(mozilla / firefox)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mozilla firefox systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox ESR 115.35.1, Thunderbird 150.0.1, and Thunderbird 140.10.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox
  • thunderbird

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-30); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
firefoxthunderbird

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-30: 2Mentions · 2026-05-04: 1Patch / Workaround · 2026-04-30: 2Technical Details · 2026-04-30: 204-3005-04
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-302
Patch2
2026-05-041
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-7320 Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox… https://www.cve.org/CVERecord?id=CVE-2026-7320

    Post summary

    The post reports CVE-2026-7320 as an information‑disclosure flaw, notes it was fixed in recent Firefox releases, and provides no PoC, exploit details, or evidence of active exploitation.

    00010163
    57.4K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Mozilla ❗ CVE-2026-7324 ❗ CVE-2026-7321 ❗ CVE-2026-7320 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mozilla-10/ https://t.co/ihwIeaAKIl

    Post summary

    The tweet provides a brief announcement of three newly identified Mozilla vulnerabilities, directing readers to external links for additional information, with no further technical or exploit details.

    00000126
    6.7K followersView on X
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-7320 Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, Firefox… https://www.cve.org/CVERecord?id=CVE-2026-7320 ----- Traducción: CVE-2026-7320 Rev… http://infoflow.cloud`

    Post summary

    CVE-2026-7320 is an information‑disclosure vulnerability in Firefox's Audio/Video component that has been fixed in version 150.0.1 (and ESR 140.10.1); there is no PoC, exploit, or evidence of active exploitation mentioned.

    0000018
    75 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---
Appmozillafirefox---
Appmozillathunderbird---
Appmozillathunderbird---

Explore more