CVE-2026-92025

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability in the Mozilla Firefox and Thunderbird DOM Navigation component allows for potential remote code execution via malicious web content.

Executive summary

A high-severity use-after-free vulnerability in the DOM Navigation component of Mozilla Firefox and Thunderbird exposes users to potential remote code execution.

Vulnerability

This is a use-after-free memory safety flaw within the DOM Navigation component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a malicious website, leading to arbitrary code execution.

Business impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the logged-in user. Given the CVSS score of 8.8, this poses a significant risk of complete system compromise, data theft, and unauthorized access to local resources. Organizations relying on these browsers for daily operations face potential disruption and severe security breaches if this flaw is weaponized.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to the identified fixed versions or the latest available release immediately.

Proactive Monitoring: Monitor browser-based traffic and endpoint security logs for signs of anomalous process execution or crashes associated with browser navigation.

Compensating Controls: Deploy endpoint protection platforms that utilize heuristic analysis to detect memory corruption attempts. Ensure that users exercise caution when browsing untrusted websites until all clients are patched.

Exploitation status

Public Exploit Available: No confirmed public exploit is available.

Analyst recommendation

The severity of this memory safety vulnerability, combined with its potential for remote code execution, necessitates immediate patching across all enterprise environments. IT administrators should prioritize the deployment of the latest Firefox and Thunderbird updates to ensure that the browser engine is protected against this high-impact flaw.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Mozilla, per the CVE Program record.