CVE-2026-92027
Mozilla · Firefox, Thunderbird
A use-after-free vulnerability exists in the DOM Streams component of Mozilla Firefox and Thunderbird, which may allow for arbitrary code execution.
Executive summary
Mozilla Firefox and Thunderbird are vulnerable to a use-after-free flaw in the DOM Streams component that could lead to remote code execution when processing malicious web content.
Vulnerability
This is a use-after-free memory corruption vulnerability located within the DOM Streams component. The vulnerability is triggered when an unauthenticated user visits a maliciously crafted webpage or interacts with specific content that causes the browser to improperly manage memory, potentially allowing an attacker to execute arbitrary code.
Business impact
Successful exploitation of this vulnerability poses a severe risk to organizational security, as it allows attackers to achieve remote code execution on the host machine. Given the CVSS score of 8.8, this flaw represents a high risk for data theft, installation of malware, or unauthorized access to sensitive internal systems. Organizations relying on these browsers for daily operations must treat this as a priority to prevent potential endpoint compromise.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the versions specified in the security advisory (Firefox 156, ESR 115.41, 140.16, 153.3 or later) immediately.
Proactive Monitoring: Monitor endpoint security logs for unexpected process crashes or suspicious behavior originating from the browser execution environment.
Compensating Controls: Ensure that browser security settings, such as site isolation and sandboxing, are fully enabled to limit the potential impact of memory corruption exploits.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The high CVSS severity and the nature of the vulnerability necessitate prompt action to protect browser-based endpoints. Administrators should deploy the required updates across the enterprise environment immediately to eliminate the risk of exploitation. Failure to patch these browsers leaves workstations vulnerable to remote code execution attacks that could bypass existing perimeter defenses.
More Mozilla CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Mozilla, per the CVE Program record.