Description
Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Corruption via Use‑After‑Free
Action: Patch
AI Analysis

Impact

The flaw is a use‑after‑free defect in the Internationalization component of Mozilla Firefox and Thunderbird. When locale data that can be influenced by an attacker is processed, the component frees an object and later accesses the same memory location, which can corrupt the heap. The corruption may change program state, but the description does not guarantee arbitrary code execution or the ability to bypass access controls. The weakness is listed as CWE‑416 and CWE‑825 and reflects a classic memory‑management error.

Affected Systems

This vulnerability applies to all releases of Mozilla Firefox and Mozilla Thunderbird that precede Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird ESR 153.3. Users running any earlier version that processes locale or internationalization data are at risk.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, and the EPSS score of less than 1 % signals a very low probability of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog, meaning no confirmed active exploits have been reported. Attackers would need to deliver crafted locale or internationalization data, likely via a local file or user‑controlled input, to trigger the flaw. Given the low exploitability metrics, the risk to broad audiences is limited.

Generated by OpenCVE AI on September 20, 2026 at 17:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Firefox 156, Firefox ESR 153.3, Thunderbird 156, or Thunderbird ESR 153.3 to apply the official fix.
  • Enable automatic updates for Firefox and Thunderbird so that future security patches are applied without delay.
  • If an immediate upgrade is not possible, remove or disable any third‑party or custom locale files that are not part of the standard installation, as they may contain vulnerable code.
  • Limit the use of externally provided locale data by restricting write privileges or sandboxing processes that load such data.

Generated by OpenCVE AI on September 20, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Internationalization component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Use-after-free in the Internationalization component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-20T00:22:31.796Z

Reserved: 2026-09-15T12:34:21.374Z

Link: CVE-2026-92060

cve-icon Vulnrichment

Updated: 2026-09-20T00:22:23.103Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:00.510

Modified: 2026-10-05T18:58:51.560

Link: CVE-2026-92060

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:21Z

Links: CVE-2026-92060 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:15:17Z

Weaknesses