Junglewise Threat Intelligence

CVE-2026-92060: Mozilla Firefox use-after-free in Internationalization component

CVE-2026-92060 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Firefox, a widely-used web browser, contains a use-after-free vulnerability in its Internationalization component that can allow remote code execution when users visit malicious websites. This flaw could enable attackers to crash the browser or gain control of user systems and access sensitive data. The vulnerability has been patched in Firefox 156 and ESR versions.

Technical details

A use-after-free vulnerability exists in Firefox's Internationalization (i18n) component, allowing memory safety violations when the browser processes certain internationalized content. The flaw is triggered through network attack vectors requiring user interaction (visiting a malicious webpage). An attacker can exploit this to achieve arbitrary code execution with the privileges of the user running Firefox. Mozilla has released patches in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3 to address this issue.

Affected products

  • Mozilla Firefox before 156
  • Mozilla Firefox ESR before 153.3
  • Mozilla Thunderbird before 156
  • Mozilla Thunderbird ESR before 153.3

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3

References

Related threats