Related Vulnerabilities: CVE-2020-6807  

A use-after-free issue has been found in Firefox before 74, in cubeb during stream destruction. When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash.

Severity Critical

Remote Yes

Type Arbitrary code execution

Description

A use-after-free issue has been found in Firefox before 74, in cubeb  during stream destruction. When a device was changed while a stream was about to be destroyed, the stream-reinit task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash.

AVG-1112 firefox 73.0.1-1 74.0-1 Critical Fixed

https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2020-6807
https://bugzilla.mozilla.org/show_bug.cgi?id=1614971