Skip to content
CVE-2026-4705 - Exploits & Severity

CVE-2026-4705 - Exploits & Severity

Feedly March 24, 2026

Undefined behavior in the WebRTC: Signaling component affecting Firefox versions below 149 and Firefox ESR versions below 140.9.

This vulnerability allows attackers to exploit undefined behavior in WebRTC signaling through network-based attacks requiring no user interaction. Successful exploitation could result in complete system compromise, including unauthorized data access (confidentiality), unauthorized data modification (integrity), and denial of service (availability). The vulnerability is remotely exploitable with low attack complexity.

There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.

Patches are available. Firefox users should update to version 149 or later. Firefox ESR users should update to version 140.9 or later.

Immediately prioritize patching all Firefox installations to version 149 or higher and all Firefox ESR installations to version 140.9 or higher. Given the HIGH severity rating, critical CVSS score of 9.8, and complete lack of prerequisites for exploitation, this should be treated as a critical security update requiring urgent deployment across your organization.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

NVD published the first details for CVE-2026-4705

Feedly found the first article mentioning CVE-2026-4705 . See article

A CVSS base score of 9.8 has been assigned.

3 changes (1 new | 2 updated):

mozilla mfsa2026-20: Security Vulnerabilities fixed in Firefox 149

CVE-2026-4705 | Mozilla Firefox up to 148 Signaling Remote Code Execution

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities

CVEs (1)

Platforms (1)