peter bassill · operator
$ cve CVE-2022-26486 JSON

CVE-2022-26486 KEV

9.6
CRITICAL · CVSS 3.1 · EPSS 2.3% (pctl 83)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-21.

Description

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

Scoring

CVSS9.6 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS2.35% — more likely to be exploited than 83% of all CVEs
WeaknessCWE-416
On CISA KEVyes — remediate by 2022-03-21
Public exploitnone known
Published2022-12-22
Last modified2026-08-19

CISA KEV

NameMozilla Firefox Use-After-Free Vulnerability
Added2022-03-07
Due2022-03-21
Vendor / productMozilla / Firefox
Ransomware usenone reported

Affected (4)

VendorProduct
mozillafirefox
mozillafirefox focus
mozillafirefox mobile
mozillathunderbird

References

→ the Explorer  ·  watch your stack  ·  NVD