CVE-2026-4705 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 24, 2026
Firefox - Undefined Behavior
Published: March 24, 2026Updated: March 24, 2026Remote Exploitable
Overview
Firefox < 149 and Firefox ESR < 140.9 contain an undefined behavior vulnerability in the WebRTC: Signaling component, letting attackers potentially cause unexpected behavior, exploit requires no special conditions.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can cause undefined behavior in the WebRTC signaling component, potentially leading to application instability or other unknown impacts.
Mitigation
Update to Firefox 149, Firefox ESR 140.9 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-4705
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- undefined
- Status
- modified
CWE
- NVD-CWE-noinfo
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H