ZeroHour

CVE-2022-26486

KEV PoC ×2mass

Use-After-Free Sandbox Escape in Mozilla Firefox and Thunderbird

CISA: Mozilla Firefox Use-After-Free Vulnerability

CVSS 3.1
9.6 critical
EPSS
2%p83
Published
()
KEV added
AI analysis

CVE-2022-26486 is a use-after-free (CWE-416) in the WebGPU inter-process communication (IPC) framework of Mozilla Firefox, triggered when the IPC framework receives an unexpected message. An attacker who can get the browser to process malicious content gains a sandbox escape from the compromised content process, and the flaw was chained with the sibling zero-day CVE-2022-26485 in attacks observed in the wild. Users of Firefox, Firefox ESR, Firefox for Android, Firefox Focus, and Thunderbird running builds prior to the patched releases are affected. Exploitation is confirmed in the wild: the issue was disclosed as a zero-day, added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, and CISA urged defenders to patch promptly. Mozilla rated the fix urgent, and the flaw carries a critical CVSS 3.1 score of 9.6 with an EPSS 30-day exploitation probability of about 2.3%.

What to do: Upgrade immediately: Firefox to 97.0.2 or later, Firefox ESR to 91.6.1 or later, Firefox for Android and Firefox Focus to 97.3.0 or later, and Thunderbird to 91.6.2 or later. Prioritize this patch because the flaw is a confirmed zero-day in CISA KEV; inventory managed endpoints for outdated Firefox/Thunderbird builds and, as an interim mitigation, consider disabling or restricting WebGPU where feasible until updates are applied.

Affected
Mozilla Firefox< 97.0.2
Mozilla Firefox ESR< 91.6.1
Mozilla Firefox for Android< 97.3.0
Mozilla Firefox Focus< 97.3.0
Mozilla Thunderbird< 91.6.2
Estimated exposure
massplausibly hundreds of millions of users (Firefox alone has roughly 200M+ active users worldwide, plus Firefox for Android and Thunderbird installs) — Firefox historically holds a low-single-digit but very large share of the multi-billion-user browser market, amounting to hundreds of millions of active users, and the affected set additionally covers Firefox ESR deployments, Firefox for…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CISA Known Exploited Vulnerability
Affected
Mozilla Firefox
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mozilla
Products
firefox, firefox focus, firefox mobile, thunderbird
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news