Junglewise Threat Intelligence

CVE-2026-92025: Mozilla Firefox use-after-free in DOM Navigation component

CVE-2026-92025 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox is a widely-used web browser that billions of users rely on for accessing the internet. A use-after-free vulnerability in the DOM Navigation component could allow an attacker to crash the browser or potentially execute arbitrary code by manipulating page navigation behavior. If exploited, this could lead to service interruption, data loss, or compromise of user systems.

Technical details

A use-after-free vulnerability exists in Firefox's DOM Navigation component, where memory is accessed after it has been freed. The vulnerability can be triggered through crafted web content that manipulates navigation behavior. Attack requires network reachability and user interaction (visiting a malicious webpage). An attacker could achieve denial of service or potentially arbitrary code execution with the privileges of the browser process. Mozilla has released patches in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, and corresponding Thunderbird versions.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 115 before 115.41, 140 before 140.16, 153 before 153.3
  • Mozilla Thunderbird before 140.16, before 153.3, before 156

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, 140.16, 153.3, Thunderbird 140.16, 153.3, 156

References

Related threats