Junglewise Threat Intelligence

CVE-2026-92028: Mozilla Firefox use-after-free in DOM Core & HTML

CVE-2026-92028 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a use-after-free vulnerability in their DOM (Document Object Model) processing for HTML content. This memory safety flaw could allow an attacker to execute arbitrary code when a user visits a malicious webpage or opens a crafted email, potentially compromising the browser or email client and accessing sensitive user data.

Technical details

A use-after-free vulnerability exists in the DOM: Core & HTML component of Firefox and Thunderbird, where memory is accessed after it has been freed. This memory safety issue in the DOM parser can be triggered via malicious HTML content delivered through a web page or email attachment. The vulnerability allows an attacker with network access (via a webpage) or adjacent access (via email) to achieve arbitrary code execution with the privileges of the browser or email client. The flaw has been patched in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 115.x before 115.41; 140.x before 140.16; 153.x before 153.3
  • Mozilla Thunderbird before 156; 140.x before 140.16; 153.x before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Firefox 156, Firefox ESR 115.41, ESR 140.16, ESR 153.3, Thunderbird 156, 140.16, 153.3

References

Related threats