Executive brief
Firefox contains a use-after-free vulnerability in the DOM Streams component that could allow attackers to execute arbitrary code when processing malicious web content. This memory safety defect affects Firefox, Firefox ESR, and Thunderbird browsers and could lead to complete browser compromise or data theft if exploited.
Technical details
A use-after-free vulnerability exists in the DOM Streams component of Firefox, Firefox ESR, and Thunderbird. The vulnerability occurs when memory is accessed after it has been freed, allowing an attacker to potentially execute arbitrary code or cause a denial of service. This is a memory corruption issue that can be triggered through web content without requiring user interaction beyond normal browsing. The vulnerability was assigned CVE-2026-92027 and has been patched in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 115.41, 140.16, 153.3
- Mozilla Thunderbird before 140.16, 153.3, 156
Timeline
- 2026-09-15: disclosed: CVE-2026-92027 published alongside Firefox 156 release
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3