CVE-2026-92058
Mozilla · Firefox and Thunderbird
A use-after-free vulnerability exists in the Graphics component of Mozilla Firefox and Thunderbird, potentially allowing for arbitrary code execution or system instability.
Executive summary
A critical use-after-free vulnerability in the Mozilla Graphics component poses a significant risk of remote code execution or application crashes for Firefox and Thunderbird users.
Vulnerability
This is a use-after-free memory corruption flaw within the Graphics component. An unauthenticated attacker can trigger this vulnerability by enticing a user to view maliciously crafted content.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high potential for severe impact. Successful exploitation could lead to full system compromise, unauthorized data access, or persistent application instability, resulting in significant operational downtime and potential loss of sensitive user information.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 156 or the 153.3 ESR release immediately to incorporate the necessary memory management fixes.
Proactive Monitoring: Review browser and application logs for unusual crashes or anomalous process behavior that may indicate attempts to trigger memory corruption.
Compensating Controls: Ensure that browser-based security features, such as sandbox protections, remain enabled to limit the potential reach of an exploit should the application be targeted.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS severity and the nature of memory corruption flaws in widely used web browsers, it is imperative that organizations prioritize the deployment of these updates. Failure to patch leaves client systems vulnerable to remote exploitation that could bypass standard security boundaries. Please ensure all instances of Firefox and Thunderbird are updated to the specified secure versions without delay.
More Mozilla CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Mozilla, per the CVE Program record.