CVE-2026-92040

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the WebAssembly component of the Mozilla Firefox and Thunderbird JavaScript engine, potentially allowing arbitrary code execution.

Executive summary

A high-severity use-after-free vulnerability in the Mozilla WebAssembly component could allow an attacker to execute arbitrary code on affected systems via malicious web content.

Vulnerability

This is a use-after-free vulnerability residing in the JavaScript WebAssembly component. The attack requires no authentication, though it does require user interaction to trigger the flaw through a malicious webpage.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for complete system compromise. Successful exploitation allows an attacker to achieve code execution in the context of the user, which could lead to unauthorized data access, the installation of malware, or complete system takeover. This presents a significant risk to organizational endpoints and internal network integrity.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 156 or later to incorporate the necessary security patches.

Proactive Monitoring: Review endpoint security logs for anomalous browser behavior or unexpected process crashes that may indicate exploitation attempts.

Compensating Controls: Use browser-based security policies or enterprise management tools to restrict the execution of untrusted WebAssembly modules if immediate patching is not possible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the critical nature of browser security, organizations should treat this update with high priority. Ensure that all systems are updated to version 156 or higher immediately to mitigate the risk of remote code execution.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Mozilla, per the CVE Program record.