Executive brief
Firefox and Thunderbird contain a use-after-free memory safety vulnerability in the GTK widget library integration. An attacker could exploit this flaw to crash the browser or email client, or potentially execute arbitrary code if the vulnerability is triggered during normal use of the application.
Technical details
A use-after-free vulnerability exists in the Widget: Gtk component affecting Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. This memory corruption flaw occurs when the application references memory that has already been freed, potentially allowing an attacker to corrupt application state or achieve code execution. The vulnerability affects Firefox versions prior to 156, Firefox ESR prior to 153.3, Thunderbird prior to 156, and Thunderbird ESR prior to 153.3. The attack likely requires user interaction (e.g., loading malicious content), and patches are available in the fixed versions.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR before 153.3
- Mozilla Thunderbird before 156
- Mozilla Thunderbird ESR before 153.3
Timeline
- 2026-09-15: disclosed: CVE-2026-92067 publicly disclosed
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3