CVE-2022-26485
KEV PoC massUse-After-Free in Mozilla Firefox XSLT Processing Exploited in the Wild
CISA: Mozilla Firefox Use-After-Free Vulnerability
CVE-2022-26485 is a use-after-free (CWE-416) in Mozilla Firefox's XSLT handling: if an XSLT parameter is removed while the stylesheet is still being processed, freed memory can be referenced, leading to exploitable memory corruption. An attacker triggers the flaw by getting a user (UI:R per the CVSS vector) to load maliciously crafted web content that invokes XSLT transformation in a vulnerable version of the browser. Successful exploitation could grant the attacker arbitrary code execution in the browser's context with the integrity and confidentiality of the user's data at risk (CVSS 3.1 8.8 High). All users of Firefox below 97.0.2, Firefox ESR below 91.6.1, Firefox for Android below 97.3.0, Firefox Focus below 97.3.0, and Thunderbird below 91.6.2 are affected. The bug was exploited as a zero-day in the wild before patches shipped, is listed in CISA's KEV (added 2022-03-07), and contemporaneous reporting tied the exploitation to a commercial spyware vendor (Variston) alongside companion flaw CVE-2022-26486.
What to do: Upgrade immediately to Firefox 97.0.2 or later, Firefox ESR 91.6.1 or later, Firefox for Android 97.3.0 or later, Firefox Focus 97.3.0 or later, and Thunderbird 91.6.2 or later, per the CISA KEV required action; there is no reliable workaround short of patching. Because the flaw was actively exploited as a zero-day and linked to targeted spyware delivery, treat endpoints that loaded untrusted web content on vulnerable versions as potentially compromised and review browser/mail host logs and EDR telemetry for follow-on activity.
| mozilla Firefox (desktop) | all versions prior to 97.0.2 |
| mozilla Firefox ESR | all versions prior to 91.6.1 |
| mozilla Firefox for Android (Firefox mobile) | all versions prior to 97.3.0 |
| mozilla Firefox Focus | all versions prior to 97.3.0 |
| mozilla Thunderbird | all versions prior to 91.6.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
- Affected
- Mozilla Firefox
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mozilla
- Products
- firefox, firefox focus, firefox mobile, thunderbird
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H