LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26485: Mozilla Firefox Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 21, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26485 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Mar 21, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution.

CVE-2022-26485 is a use-after-free vulnerability in Mozilla Firefox that arises during XSLT parameter processing. Successful exploitation can allow an attacker to achieve arbitrary code execution on the affected system. IT and security teams should treat this as a high-priority browser issue because Firefox is widely deployed on endpoints and the flaw can be triggered through crafted web content.

Public detail is limited to the CISA summary and the CWE classification; confirm exact affected builds, fixed releases, and any additional technical notes directly against the Mozilla vendor advisory before acting.

How it works

The weakness is classified as CWE-416 (Use After Free). In this class of flaw, memory that has already been freed is later referenced again. When the browser processes certain XSLT parameters, the use-after-free condition can leave the process in an inconsistent state that an attacker may abuse to execute arbitrary code in the context of the Firefox process.

An attacker would typically need to lure a user to malicious or attacker-controlled web content that exercises the vulnerable XSLT parameter handling path. No further exploit mechanics are provided in the available facts; treat any public proof-of-concept claims with caution and validate them only against official vendor or trusted researcher disclosures.

Am I affected? How to find it in your systems

Mozilla Firefox is commonly installed on Windows, macOS, and Linux workstations, VDI images, and developer or kiosk systems. Inventory every endpoint and managed browser deployment for the presence of Firefox.

How to remediate

The primary remediation is to apply the updates issued by Mozilla. Follow the vendor instructions referenced in the CISA required action: obtain and deploy the security update that addresses CVE-2022-26485 through your normal patch-management process.

If you can't patch immediately

If immediate patching is not possible, apply compensating controls to reduce exposure until the vendor update can be installed.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to endpoint compromise and subsequent data theft. The available facts do not document ransomware use associated with this CVE. If you suspect exploitation, isolate the affected host, preserve forensic evidence, and begin incident-response procedures. As a quick additional check, users can run a free exposure scan of their email addresses against known breach data sets to see whether credentials or personal information have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMozilla · Firefox
WeaknessCWE-416
Added to CISA KEVMar 7, 2022
Federal patch deadlineMar 21, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities