LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2022-26486: Mozilla Firefox Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 7, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 21, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2022-26486 to its Known Exploited Vulnerabilities catalog on Mar 7, 2022, with a federal patch deadline of Mar 21, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.

CVE-2022-26486 is a use-after-free vulnerability in Mozilla Firefox's WebGPU IPC Framework. An attacker who successfully exploits it can achieve arbitrary code execution on the affected system. This matters because Firefox is widely deployed on endpoints; a browser flaw of this class can turn a malicious or compromised web page into a full compromise of the user session or host, so IT and security teams need to confirm exposure and remediate promptly.

CISA notes the vulnerability allows arbitrary code execution and directs organizations to apply updates per vendor instructions. Known ransomware use is not documented for this CVE. Specifics such as exact affected builds must be confirmed against the Mozilla advisory.

How it works

The weakness is CWE-416 (use-after-free). In this pattern, memory is freed while a pointer to it remains in use; later access through that dangling pointer can corrupt memory or redirect control flow. According to the CISA summary, the flaw resides in Firefox's WebGPU IPC Framework. An attacker who can trigger the vulnerable code path—typically by causing the browser to process crafted WebGPU-related content—may be able to execute arbitrary code in the context of the browser process.

Exact trigger conditions, required user interaction, and sandbox escape details are not provided in the given facts; defenders should treat any successful exploitation as capable of code execution and should rely on the vendor advisory for precise mechanics and impact.

Am I affected? How to find it in your systems

The affected product is Mozilla Firefox. It commonly runs on Windows, macOS, and Linux desktops and laptops, and may also appear in VDI images, kiosks, or developer workstations. Inventory every system that has Firefox installed, including portable or secondary installations.

How to remediate

Patch first. Apply the Mozilla updates that address CVE-2022-26486 exactly as directed in the vendor advisory and in line with CISA's required action to apply updates per vendor instructions. Deploy the fixed build through your standard software-update or endpoint-management process, then verify installation on a sample of hosts.

If you can't patch immediately

Until the vendor update can be applied, reduce risk with compensating controls while maintaining a clear timeline to patch.

If your data may have been exposed

Actively exploited browser vulnerabilities can lead to endpoint compromise and subsequent data theft. If you have reason to believe systems were targeted before patching, follow your incident-response process: isolate affected hosts, preserve evidence, and hunt for persistence or lateral movement. Known ransomware use is not documented for this CVE, but code execution still warrants full investigation. You can run a free exposure scan of your email addresses to check whether credentials or personal data already appear in known breach collections, then force password resets and review access logs accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMozilla · Firefox
WeaknessCWE-416
Added to CISA KEVMar 7, 2022
Federal patch deadlineMar 21, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities