Junglewise Threat Intelligence

CVE-2026-92023: Mozilla Firefox use-after-free in XML component

CVE-2026-92023 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a use-after-free vulnerability in their XML processing component that could allow attackers to crash the application or execute arbitrary code. An attacker could exploit this by crafting a malicious XML document and convincing a user to open it in the affected browser or email client, potentially compromising system security and user data.

Technical details

A use-after-free vulnerability exists in the XML component of Firefox and Thunderbird where memory is accessed after being freed, potentially allowing memory corruption. The vulnerability requires user interaction (opening a malicious XML document) and is reachable over the network through a crafted web page or email attachment. Successful exploitation could lead to arbitrary code execution with the privileges of the affected application. Mozilla has issued patches in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 115 before 115.41; 140 before 140.16; 153 before 153.3
  • Mozilla Thunderbird before 156; 140 before 140.16; 153 before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched

References

Related threats