CVE-2026-92040
Mozilla · Firefox, Thunderbird
A use-after-free vulnerability exists in the WebAssembly component of the Mozilla Firefox and Thunderbird JavaScript engine, potentially allowing arbitrary code execution.
Executive summary
A high-severity use-after-free vulnerability in the Mozilla WebAssembly component could allow an attacker to execute arbitrary code on affected systems via malicious web content.
Vulnerability
This is a use-after-free vulnerability residing in the JavaScript WebAssembly component. The attack requires no authentication, though it does require user interaction to trigger the flaw through a malicious webpage.
Business impact
The vulnerability carries a CVSS score of 8.8, reflecting its potential for complete system compromise. Successful exploitation allows an attacker to achieve code execution in the context of the user, which could lead to unauthorized data access, the installation of malware, or complete system takeover. This presents a significant risk to organizational endpoints and internal network integrity.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 156 or later to incorporate the necessary security patches.
Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process crashes that may indicate exploitation attempts.
Compensating Controls: Use browser-based security policies or enterprise management tools to restrict the execution of untrusted WebAssembly modules if immediate patching is not possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS severity and the critical nature of browser security, organizations should treat this update with high priority. Ensure that all systems are updated to version 156 or higher immediately to mitigate the risk of remote code execution.
More Mozilla CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Mozilla, per the CVE Program record.