CVE-2022-26486
CVSS Score
9.6
EPSS Score
0.0%
EPSS Percentile
0th
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
| Vendor | mozilla |
| Product | firefox |
| Ecosystems | |
| Industries | Technology |
| Published | Dec 22, 2022 |
| Last Updated | Oct 21, 2025 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for mozilla firefox
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2022-26486.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Mozilla / Firefox
unspecified < 97.0.2
Mozilla / Firefox ESR
unspecified < 91.6.1
Mozilla / Firefox for Android
unspecified < 97.3.0
Mozilla / Thunderbird
unspecified < 91.6.2
Mozilla / Focus
unspecified < 97.3.0