Buffer overflow in Mozilla products - CVE-2026-8092
Published: May 7, 2026
Vulnerability identifier: #VU130583
CSH Severity: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-8092
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Firefox for Android
Mozilla Firefox
Firefox ESR
Firefox for Android
Software vendor:
Mozilla
Mozilla
Description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption when processing web content. A remote attacker can trigger memory corruption using specially crafted content to execute arbitrary code.
Some of the reported bugs showed evidence of memory corruption.
Remediation
Install security update from vendor's website.
External links
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-42/
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=1806249
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2021977
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022576
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022722
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2024439
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2027883
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029463
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2030323
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2032042
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2032043
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2033270
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2033637
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2034422
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2034496
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2035879
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2036516
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-41/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-40/