CRITICAL

CVE-2022-26486

Mozilla Firefox 2022-12-22 CVSS v3.1
CVSS
9.6
KEV

Description

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

Summary dbcve.org

A use-after-free vulnerability in Firefox's WebGPU IPC framework allows an unexpected IPC message to corrupt memory, potentially enabling a sandbox escape. This critical flaw has been exploited in the wild.

Mitigation

Apply vendor-supplied patches by updating affected products to Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, Thunderbird 91.6.2, or Focus 97.3.0 respectively.

Proof of Concept

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

2.35%
Probability of exploitation in next 30 days
82.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE