Mozilla fixes Firefox zero-days exploited in the wild (CVE-2022-26485, CVE-2022-26486)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-26486 +1 in the same advisory: …26485 | Use-After-Free Sandbox Escape in Mozilla Firefox and Thunderbird CVE-2022-26486 is a use-after-free (CWE-416) in the WebGPU inter-process communication (IPC) framework of Mozilla Firefox, triggered when the IPC framework receives an unexpected message. An attacker who can get the browser to process malicious content gains a sandbox escape from the compromised content process, and the flaw was chained with the sibling zero-day CVE-2022-26485 in attacks observed in the wild. Users of Firefox, Firefox ESR, Firefox for Android, Firefox Focus, and Thunderbird running builds prior to the patched releases are affected. Exploitation is confirmed in the wild: the issue was disclosed as a zero-day, added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, and CISA urged defenders to patch promptly. Mozilla rated the fix urgent, and the flaw carries a critical CVSS 3.1 score of 9.6 with an EPSS 30-day exploitation probability of about 2.3%. Do: Upgrade immediately: Firefox to 97.0.2 or later, Firefox ESR to 91.6.1 or later, Firefox for Android and Firefox Focus to 97.3.0 or later, and Thunderbird to 91.6.2 or later. Prioritize this patch because the flaw is a confirmed zero-day in CISA KEV; inventory managed endpoints for outdated Firefox/Thunderbird builds and, as an interim mitigation, consider disabling or restricting WebGPU where feasible until updates are applied. | 9.6 group max | 2% | KEV PoC ×2 |
| massplausibly hundreds of millions of users (Firefox alone has roughly 200M+ active users worldwide, plus Firefox for Android and Thunderbird installs) |
Full article260 words · extracted from helpnetsecurity.com · click to collapse
Mozilla has released an out-of-band security update for Firefox, Firefox Focus, and Thunderbird, fixing two critical vulnerabilities (CVE-2022-26485, CVE-2022-26486) exploited by attackers in the wild.

About the vulnerabilities (CVE-2022-26485, CVE-2022-26486)
The two patched zero-days are both memory corruption bugs of the “use-after-free” kind, meaning that they may allow attackers to use memory that has been freed by the program.
CVE-2022-26485 affects XSLT parameter processing and can be used to achieve remote code execution within the context of the application.
CVE-2022-26486 affects the WebGPU IPC Framework and allows attackers to perform a sandbox escape.
Both flaws have been reported by Wang Gang, Liu Jialei, Du Sihang, Huang Yi & Yang Kang of 360 ATA, so it seems safe to assume they are being used together to compromise machines remotely and allow malware to escape the application’s security sandbox.
Mozilla has chosen not to share more details about the vulnerabilities or the attacks, and has urged users to upgrade to:
- Firefox 97.0.2
- Firefox ESR 91.6.1
- Firefox for Android 97.3
- Focus 97.3
- Thunderbird 91.6.2
Updating the software
While the number of Firefox users has been steadily declining over the last decade, it is still used by millions of users. According to Mozilla’s user activity statistics, nearly 215 million Firefox desktop clients have been active in the past 28 days.
Firefox releases major updates roughly every 50 days, but if the situation warrants – like in this case – out-of-band security updates are pushed out.
Users of the affected software should check for this one and implement it as soon as possible.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/03/07/cve-2022-26485-cve-2022-26486/