CVE-2026-92067
Mozilla · Firefox, Thunderbird
A use-after-free vulnerability exists in the Widget: Gtk component of Mozilla Firefox and Thunderbird, which could allow for memory corruption and potential code execution.
Executive summary
A critical use-after-free vulnerability in the Gtk component of Mozilla Firefox and Thunderbird exposes users to remote code execution risks.
Vulnerability
This is a use-after-free memory corruption flaw located within the Widget: Gtk component. The vulnerability is triggered via network interaction and requires user interaction, such as visiting a malicious webpage.
Business impact
The CVSS score of 8.8 reflects the high risk associated with this vulnerability, as successful exploitation can lead to a complete compromise of the application process. This may result in unauthorized data access, the installation of malicious software, or system instability. Organizations relying on Firefox or Thunderbird for critical operations face significant reputational and security risks if these applications are not promptly patched.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 156 or the ESR version 153.3 immediately.
Proactive Monitoring: Review endpoint security logs for signs of anomalous application crashes or unexpected memory usage patterns associated with Firefox or Thunderbird.
Compensating Controls: Use endpoint protection software to block known malicious domains and ensure that browser-based security features are enabled to mitigate the impact of web-based attacks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability, administrators should prioritize the deployment of the provided security updates across all managed endpoints. Failure to patch these browsers leaves users exposed to potential remote code execution attacks triggered by simple web navigation. Ensure that all users are prompted to restart their applications to finalize the update process.
More Mozilla CVEs all →
History
CVE Brief tracked this CVE 4 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.8 (3.1)
- Analyst report written
Sources
Originally found and disclosed by Mozilla, per the CVE Program record.