March 7, 2022 · Applied Cybernetics Group
CVE-2022-26485 — Mozilla Firefox
Mozilla Firefox Use-After-Free Vulnerability
- Added to KEV
2022-03-07- Federal due date
2022-03-21- Vendor
- Mozilla
- Product
- Firefox
- EPSS
- 96.4th percentile (score 0.143, as of
2026-09-16) - NVD CVSS v3.1
- 8.8 (HIGH)
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-26485
CISA short description
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.
Required action
Apply updates per vendor instructions.
NVD description
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.