ZeroHour

CVE-2022-26485

KEV PoC mass

Use-After-Free in Mozilla Firefox XSLT Processing Exploited in the Wild

CISA: Mozilla Firefox Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
14%p96
Published
()
KEV added
AI analysis

CVE-2022-26485 is a use-after-free (CWE-416) in Mozilla Firefox's XSLT handling: if an XSLT parameter is removed while the stylesheet is still being processed, freed memory can be referenced, leading to exploitable memory corruption. An attacker triggers the flaw by getting a user (UI:R per the CVSS vector) to load maliciously crafted web content that invokes XSLT transformation in a vulnerable version of the browser. Successful exploitation could grant the attacker arbitrary code execution in the browser's context with the integrity and confidentiality of the user's data at risk (CVSS 3.1 8.8 High). All users of Firefox below 97.0.2, Firefox ESR below 91.6.1, Firefox for Android below 97.3.0, Firefox Focus below 97.3.0, and Thunderbird below 91.6.2 are affected. The bug was exploited as a zero-day in the wild before patches shipped, is listed in CISA's KEV (added 2022-03-07), and contemporaneous reporting tied the exploitation to a commercial spyware vendor (Variston) alongside companion flaw CVE-2022-26486.

What to do: Upgrade immediately to Firefox 97.0.2 or later, Firefox ESR 91.6.1 or later, Firefox for Android 97.3.0 or later, Firefox Focus 97.3.0 or later, and Thunderbird 91.6.2 or later, per the CISA KEV required action; there is no reliable workaround short of patching. Because the flaw was actively exploited as a zero-day and linked to targeted spyware delivery, treat endpoints that loaded untrusted web content on vulnerable versions as potentially compromised and review browser/mail host logs and EDR telemetry for follow-on activity.

Affected
mozilla Firefox (desktop)all versions prior to 97.0.2
mozilla Firefox ESRall versions prior to 91.6.1
mozilla Firefox for Android (Firefox mobile)all versions prior to 97.3.0
mozilla Firefox Focusall versions prior to 97.3.0
mozilla Thunderbirdall versions prior to 91.6.2
Estimated exposure
mass≈100M+ users (Firefox alone has hundreds of millions of active users, plus large Firefox ESR enterprise fleets and tens of millions of Thunderbird installs) — Firefox is one of the world's most widely deployed desktop browsers with an install base in the hundreds of millions, Firefox ESR is the default browser baseline in many managed environments, and Thunderbird ships as the default mail…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CISA Known Exploited Vulnerability
Affected
Mozilla Firefox
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mozilla
Products
firefox, firefox focus, firefox mobile, thunderbird
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news