Junglewise Threat Intelligence

CVE-2026-92016: Mozilla Firefox use-after-free in Disability Access APIs

CVE-2026-92016 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox's accessibility features contain a use-after-free vulnerability that could allow an attacker to crash the browser or potentially execute arbitrary code. This affects the components that enable assistive technology tools (screen readers, voice control, magnification software) to interact with web content. Users relying on accessibility features or running Firefox in enterprise environments could face service disruptions or security breaches.

Technical details

A use-after-free vulnerability exists in Firefox's Disability Access APIs component, where memory is referenced after being freed, potentially leading to memory corruption. The vulnerability is remotely exploitable via malicious web content and does not require prior authentication or user interaction beyond normal browsing. An attacker can craft web pages that trigger the use-after-free condition, resulting in denial of service or potential arbitrary code execution with browser privileges. The vulnerability has been patched in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 140.0–140.15, 153.0–153.2
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird ESR 140.0–140.15, 153.0–153.2

Timeline

  • 2026-09-15: disclosed: Publicly disclosed in Mozilla Foundation Security Advisory MFSA2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3

References

Related threats