CVE-2026-92027

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the DOM Streams component of Mozilla Firefox and Thunderbird, which may allow for arbitrary code execution.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a use-after-free flaw in the DOM Streams component that could lead to remote code execution when processing malicious web content.

Vulnerability

This is a use-after-free memory corruption vulnerability located within the DOM Streams component. The vulnerability is triggered when an unauthenticated user visits a maliciously crafted webpage or interacts with specific content that causes the browser to improperly manage memory, potentially allowing an attacker to execute arbitrary code.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it allows attackers to achieve remote code execution on the host machine. Given the CVSS score of 8.8, this flaw represents a high risk for data theft, installation of malware, or unauthorized access to sensitive internal systems. Organizations relying on these browsers for daily operations must treat this as a priority to prevent potential endpoint compromise.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to the versions specified in the security advisory (Firefox 156, ESR 115.41, 140.16, 153.3 or later) immediately.

Proactive Monitoring: Monitor endpoint security logs for unexpected process crashes or suspicious behavior originating from the browser execution environment.

Compensating Controls: Ensure that browser security settings, such as site isolation and sandboxing, are fully enabled to limit the potential impact of memory corruption exploits.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high CVSS severity and the nature of the vulnerability necessitate prompt action to protect browser-based endpoints. Administrators should deploy the required updates across the enterprise environment immediately to eliminate the risk of exploitation. Failure to patch these browsers leaves workstations vulnerable to remote code execution attacks that could bypass existing perimeter defenses.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Mozilla, per the CVE Program record.