Executive brief
Firefox is a widely-used web browser used by millions to access websites and online services. A use-after-free vulnerability in the Graphics component could allow an attacker to execute arbitrary code when a user visits a malicious website, potentially compromising the user's system and sensitive data. The vulnerability affects Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR versions prior to the patched releases.
Technical details
CVE-2026-92058 is a use-after-free memory safety vulnerability in the Graphics component of Mozilla Firefox and Thunderbird. The vulnerability allows an attacker to trigger a crash or potentially achieve arbitrary code execution by exploiting improper memory management in the Graphics subsystem. The attack is network-based and requires user interaction (visiting a malicious website or opening a crafted file). Mozilla addressed this vulnerability in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92058 publicly disclosed
- 2026-09-15: patched: Fixes released in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3