Use-after-free in Mozilla products - CVE-2026-92022
Published: September 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to use-after-free in the DOM: HTML Parser component when parsing web content. A remote attacker can trick the victim into visiting a specially crafted website to cause memory corruption.
User interaction is required to visit the crafted website.
Affected software
Firefox ESR
Firefox for Android
How to mitigate CVE-2026-92022
Firefox for Android - update to 156.0
Firefox ESR - addressed in versions 115.41.0, 140.16.0, 153.3.0