CVE-2026-92067

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability exists in the Widget: Gtk component of Mozilla Firefox and Thunderbird, which could allow for memory corruption and potential code execution.

Executive summary

A critical use-after-free vulnerability in the Gtk component of Mozilla Firefox and Thunderbird exposes users to remote code execution risks.

Vulnerability

This is a use-after-free memory corruption flaw located within the Widget: Gtk component. The vulnerability is triggered via network interaction and requires user interaction, such as visiting a malicious webpage.

Business impact

The CVSS score of 8.8 reflects the high risk associated with this vulnerability, as successful exploitation can lead to a complete compromise of the application process. This may result in unauthorized data access, the installation of malicious software, or system instability. Organizations relying on Firefox or Thunderbird for critical operations face significant reputational and security risks if these applications are not promptly patched.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to version 156 or the ESR version 153.3 immediately.

Proactive Monitoring: Review endpoint security logs for signs of anomalous application crashes or unexpected memory usage patterns associated with Firefox or Thunderbird.

Compensating Controls: Use endpoint protection software to block known malicious domains and ensure that browser-based security features are enabled to mitigate the impact of web-based attacks.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this vulnerability, administrators should prioritize the deployment of the provided security updates across all managed endpoints. Failure to patch these browsers leaves users exposed to potential remote code execution attacks triggered by simple web navigation. Ensure that all users are prompted to restart their applications to finalize the update process.

More Mozilla CVEs all →

History

CVE Brief tracked this CVE 4 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.8 (3.1)
  4. Analyst report written

Sources

Originally found and disclosed by Mozilla, per the CVE Program record.