CVE-2022-26486
KEV PoC ×2massUse-After-Free Sandbox Escape in Mozilla Firefox and Thunderbird
CISA: Mozilla Firefox Use-After-Free Vulnerability
CVE-2022-26486 is a use-after-free (CWE-416) in the WebGPU inter-process communication (IPC) framework of Mozilla Firefox, triggered when the IPC framework receives an unexpected message. An attacker who can get the browser to process malicious content gains a sandbox escape from the compromised content process, and the flaw was chained with the sibling zero-day CVE-2022-26485 in attacks observed in the wild. Users of Firefox, Firefox ESR, Firefox for Android, Firefox Focus, and Thunderbird running builds prior to the patched releases are affected. Exploitation is confirmed in the wild: the issue was disclosed as a zero-day, added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, and CISA urged defenders to patch promptly. Mozilla rated the fix urgent, and the flaw carries a critical CVSS 3.1 score of 9.6 with an EPSS 30-day exploitation probability of about 2.3%.
What to do: Upgrade immediately: Firefox to 97.0.2 or later, Firefox ESR to 91.6.1 or later, Firefox for Android and Firefox Focus to 97.3.0 or later, and Thunderbird to 91.6.2 or later. Prioritize this patch because the flaw is a confirmed zero-day in CISA KEV; inventory managed endpoints for outdated Firefox/Thunderbird builds and, as an interim mitigation, consider disabling or restricting WebGPU where feasible until updates are applied.
| Mozilla Firefox | < 97.0.2 |
| Mozilla Firefox ESR | < 91.6.1 |
| Mozilla Firefox for Android | < 97.3.0 |
| Mozilla Firefox Focus | < 97.3.0 |
| Mozilla Thunderbird | < 91.6.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
- Affected
- Mozilla Firefox
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mozilla
- Products
- firefox, firefox focus, firefox mobile, thunderbird
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H