CVE-2026-92049

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the Widget: Win32 component of Mozilla Firefox and Thunderbird, potentially allowing arbitrary code execution upon processing malicious content.

Executive summary

Mozilla Firefox and Thunderbird are affected by a high-severity use-after-free vulnerability in the Win32 component that could lead to remote code execution when triggered by a user.

Vulnerability

This is a use-after-free memory corruption flaw within the Widget: Win32 component. The vulnerability is exploitable by an unauthenticated remote attacker through a specially crafted web page or message that forces the application to interact with freed memory.

Business impact

Successful exploitation of this memory corruption vulnerability can lead to arbitrary code execution within the context of the user running the browser or mail client. Given the CVSS score of 8.8, this flaw represents a significant risk to organizational endpoints, potentially facilitating system compromise, unauthorized data exfiltration, or the installation of persistent malware.

Remediation

Immediate Action: Upgrade to Firefox 156, Firefox ESR 153.3, Thunderbird 156, or Thunderbird 153.3 immediately. Organizations should utilize centralized deployment tools to push these security updates to all managed endpoints.

Proactive Monitoring: Review endpoint security logs for signs of anomalous process crashes or unexpected child process spawning related to the browser or mail client.

Compensating Controls: While no direct WAF mitigation exists for this client-side flaw, ensure that browser-based security policies and endpoint detection and response tools are active to monitor for suspicious process behavior.

Exploitation status

Public Exploit Available: No confirmed public exploit (none).

Analyst recommendation

The severity of this vulnerability, combined with the potential for remote code execution, necessitates an immediate update cycle. Administrators must prioritize the deployment of the provided security versions across the enterprise to eliminate the risk of exploitation.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Mozilla, per the CVE Program record.