Junglewise Threat Intelligence

CVE-2026-92046: Mozilla Firefox use-after-free in Graphics component

CVE-2026-92046 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox and Thunderbird contain a use-after-free vulnerability in the Graphics rendering component that could allow an attacker to crash the application or potentially execute arbitrary code. This vulnerability affects millions of users and could be exploited by serving malicious web content. Mozilla has released security updates for Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3 to address this issue.

Technical details

A use-after-free vulnerability exists in the Graphics component of Firefox and Thunderbird, allowing attackers to access memory that has been freed. The vulnerability can be triggered through malicious web content or graphics rendering operations that cause the application to reference deallocated memory. Attack precondition is minimal—a user needs only visit a malicious website or open a specially crafted document. An attacker can leverage this flaw to crash the application (denial of service) or potentially achieve arbitrary code execution with the privileges of the affected application. Patches are available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird before 153.3

Timeline

  • 2026-09-15: disclosed: CVE-2026-92046 publicly disclosed
  • 2026-09-15: patched: Fixes available in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats