Junglewise Threat Intelligence

CVE-2026-92024: Mozilla Firefox use-after-free in SVG component

CVE-2026-92024 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird web browsers contain a use-after-free vulnerability in the SVG (Scalable Vector Graphics) processing component. An attacker can exploit this flaw through a malicious SVG file to crash the browser or potentially execute arbitrary code, compromising user data and system security.

Technical details

A use-after-free vulnerability exists in the SVG component of Firefox and Thunderbird browsers. The flaw occurs when memory is dereferenced after being freed, allowing potential memory corruption. An attacker can craft a malicious SVG document and deliver it to a user via the web or email; user interaction (opening or viewing the SVG) is required to trigger the vulnerability. Successful exploitation can lead to application crash (denial of service) or arbitrary code execution within the browser's security context. Patches are available in Firefox 156, Firefox ESR 115.41/140.16/153.3, and Thunderbird 140.16/153.3/156.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 115.41, before 140.16, before 153.3
  • Mozilla Thunderbird before 140.16, before 153.3, before 156

Timeline

  • 2026-09-15: disclosed: Vulnerability announced in Mozilla Foundation Security Advisory 2026-90
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3

References

Related threats