Junglewise Threat Intelligence

CVE-2022-26486: Mozilla Firefox Use-After-Free Vulnerability

CVE-2022-26486 · Severity: critical · CVSS 9.6 · Exploited in the wild · Published 2022-03-07

Technologies: Mozilla Thunderbird, Mozilla Firefox for Android, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A use-after-free vulnerability exists in the Mozilla WebGPU IPC framework due to the processing of unexpected messages. This flaw can be exploited to achieve a sandbox escape and arbitrary code execution.

Affected products

  • Mozilla Firefox < 97.0.2
  • Mozilla Firefox ESR < 91.6.1
  • Mozilla Firefox for Android < 97.3.0
  • Mozilla Thunderbird < 91.6.2
  • Mozilla Focus < 97.3.0

Timeline

  • 2022-03-07: disclosed
  • 2022-03-07: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-03-07: exploited: Reports of attacks in the wild abusing this flaw.
  • 2022-12-22: advisory: NVD Published Date

Related threats