March 7, 2022 · Applied Cybernetics Group
CVE-2022-26486 — Mozilla Firefox
Mozilla Firefox Use-After-Free Vulnerability
- Added to KEV
2022-03-07- Federal due date
2022-03-21- Vendor
- Mozilla
- Product
- Firefox
- EPSS
- 82.8th percentile (score 0.023, as of
2026-09-16) - NVD CVSS v3.1
- 9.6 (CRITICAL)
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2022-26486
CISA short description
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.
Required action
Apply updates per vendor instructions.
NVD description
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.