Use-after-free in Firefox for Android and Mozilla Firefox - CVE-2022-45407
Published: November 15, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error when using FontFace() on a background worker. A remote attacker can trick the victim to visit a specially crafted website, trigger a use-after-free error and execute arbitrary code on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.
Affected software
Mozilla Firefox
Gentoo Linux
Ubuntu
www-client/firefox
firefox (Ubuntu package)
How to mitigate CVE-2022-45407
Mozilla Firefox - update to 107.0
www-client/firefox - update to 104
firefox (Ubuntu package) - addressed in versions 107.0+build2-0ubuntu0.18.04.1, 107.0+build2-0ubuntu0.20.04.1