Junglewise Threat Intelligence

CVE-2026-92029: Mozilla Firefox use-after-free in SVG component

CVE-2026-92029 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox is a widely-used web browser that millions of users rely on to access the internet securely. A use-after-free vulnerability in its SVG (vector graphics) rendering component could allow an attacker to crash the browser or potentially execute malicious code when a user visits a compromised website containing specially crafted SVG content. This could lead to data theft, malware infection, or other compromise of the affected system.

Technical details

A use-after-free vulnerability exists in the SVG component of Firefox, where memory is accessed after it has been freed, potentially leading to memory corruption. The vulnerability is triggered when processing certain SVG elements or operations, and no authentication or special user interaction beyond visiting a malicious page is required. An attacker can exploit this by hosting malicious SVG content on a website and waiting for users to visit; successful exploitation could result in arbitrary code execution in the context of the browser process. Mozilla has patched this vulnerability in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, and corresponding Thunderbird releases.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR 115 before 115.41, 140 before 140.16, 153 before 153.3
  • Mozilla Thunderbird before 156, 140 before 140.16, 153 before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3

References

Related threats