CVE-2022-26485: high-severity vulnerability in Mozilla Firefox
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
A flaw in XSLT parameter handling allowed attackers to exploit a use-after-free vulnerability, potentially crashing the browser or executing malicious code. This bug affected multiple Firefox products and was actively exploited in real attacks.
Use-after-free vulnerability (CWE-416) in XSLT parameter processing where improper memory management during parameter removal could be leveraged for arbitrary code execution. Remote attack vector requiring user interaction (opening malicious content); impacts Firefox, Firefox ESR, Firefox Android, Thunderbird, and Focus versions prior to specified patches.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.