Mozilla security advisory-CVE-2022-26486
NAME
Mozilla Foundation – Multiple
- Platforms Affected:
Multiple - Risk Level:
high - CVE Type:
Use after free
DESCRIPTION
CVE-2022-26486 is a use after free vulnerability impacting Mozilla Firefox versions 97.0.1 and earlier, Mozilla Firefox ESR versions 91.6.0 and earlier, Mozilla Firefox for Android versions 97.2.0 and earlier and Mozilla Focus versions 97.2.0 and earlier. A proof of concept (PoC) was not observed publicly or in the underground. Mozilla claimed to be aware of the vulnerability being actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE:
- CVSS 3.0 SCORE:
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://www[.]mozilla[.]org/en-US/security/advisories/mfsa2022-09/
MITIGATION
Mozilla Foundation addressed the vulnerability in a security advisory with updated versions.
- Reference Link:
https://www.mozilla.org/en-US/security/advisories/mfsa2022-09/ - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.