Junglewise Threat Intelligence

CVE-2022-26485: Mozilla Firefox Use-After-Free Vulnerability

CVE-2022-26485 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-03-07

Technologies: Mozilla Thunderbird, Mozilla Firefox for Android, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox and related products contain a use-after-free vulnerability in XSLT parameter processing. Removing an XSLT parameter during processing can lead to memory corruption, which may be exploited to achieve arbitrary code execution.

Affected products

  • Mozilla Firefox < 97.0.2
  • Mozilla Firefox ESR < 91.6.1
  • Mozilla Firefox for Android < 97.3.0
  • Mozilla Thunderbird < 91.6.2
  • Mozilla Focus < 97.3.0

Timeline

  • 2022-03-07: disclosed: Vulnerability published and added to CISA KEV catalog.
  • 2022-03-07: kev added
  • 2022-03-07: exploited: Reports of attacks in the wild abusing this flaw.

Related threats