CVE-2026-92056

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the Graphics: Text component of Mozilla Firefox and Thunderbird, potentially allowing remote code execution.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a use-after-free flaw in the Graphics: Text component that could result in arbitrary code execution via a specially crafted web page.

Vulnerability

This is a use-after-free memory corruption vulnerability located in the Graphics: Text component. The flaw is triggered when an unauthenticated remote attacker lures a user to visit a malicious site, causing the application to access memory that has already been deallocated.

Business impact

The exploitation of this vulnerability presents a significant risk to organizational security, as it allows for remote code execution with the privileges of the victim user. Successful exploitation could lead to full system compromise, the theft of sensitive browser-stored credentials, or the installation of persistent malware. Given the CVSS score of 8.8, this vulnerability is classified as High severity and requires immediate attention to prevent potential data breaches or unauthorized administrative control over endpoints.

Remediation

Immediate Action: Organizations must update Mozilla Firefox and Thunderbird to version 156, or to version 153.3 for users on the Extended Support Release (ESR) channel, to apply the security patches.

Proactive Monitoring: Security teams should monitor endpoint logs for unusual browser crashes or unexpected child process spawning, which may indicate attempted exploitation of memory corruption flaws.

Compensating Controls: While there is no direct virtual patch for use-after-free vulnerabilities, employing endpoint detection and response (EDR) solutions can help identify and block malicious activity originating from web browsers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of memory corruption vulnerabilities within web browsers, administrators should prioritize the deployment of the provided patches across all workstations. Ensuring that automated update mechanisms are enabled for Firefox and Thunderbird will minimize the window of exposure. Failure to remediate this vulnerability leaves endpoints susceptible to remote compromise through routine web browsing activities.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by r00tdaddy, per the CVE Program record.