Description
Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use-after-free flaw exists in the graphics component of Firefox and Thunderbird. The flaw allows an attacker to corrupt memory after the original object has been freed, potentially enabling the execution of arbitrary code. Because the vulnerability can affect both the browser and mail client, it can compromise confidentiality, integrity, and availability of the affected system if exploited successfully.

Affected Systems

Mozilla publishes this vulnerability for Firefox versions before 156, Firefox ESR before 153.3, and Thunderbird before 156. Users running any of these outdated releases are impacted.

Risk and Exploitability

The CVSS score is not provided, and no EPSS value is available, but the nature of a use-after-free typically signals a high severity risk. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, triggered through rendered web or email content that exercises the graphics component. The conditions for exploitation would require the attacker to supply crafted graphical data that is processed by the victim’s application.

Generated by OpenCVE AI on September 16, 2026 at 04:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 156 or newer, or to Firefox ESR 153.3 or newer.
  • Upgrade Thunderbird to version 156 or newer.
  • Keep the application updated automatically and monitor vendor advisories for further patches or mitigations.

Generated by OpenCVE AI on September 16, 2026 at 04:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-667

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Use-after-free in the Graphics component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-16T14:24:41.682Z

Reserved: 2026-09-15T12:34:19.276Z

Link: CVE-2026-92058

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T13:17:00.207

Modified: 2026-09-16T19:34:05.910

Link: CVE-2026-92058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-16T04:30:11Z

Weaknesses