Description
Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Use‑after‑free within the Gtk widget used by Mozilla applications can corrupt memory, potentially allowing an attacker to execute arbitrary code or elevate privileges in the context of the user. The flaw is classified as a high‑severity vulnerability with a CVSS score of 8.8, meaning it can lead to severe impact beyond a simple crash. The underlying weakness, a use‑after‑free, is listed as CWE‑416, and its misuse in rendering can also trigger a denial of service.

Affected Systems

The affected products are Mozilla Firefox and Mozilla Thunderbird. All releases older than Firefox 156, Firefox ESR 153.3, and Thunderbird 156 are susceptible. Users running versions before these releases should consider them vulnerable until the recommended update is applied. No specific operating system or platform is singled out; the flaw resides in the Gtk component shared across all supported platforms.

Risk and Exploitability

The likelihood of exploitation remains low, with an EPSS score of <1% and absence from the CISA KEV catalog. However, the vulnerability’s high CVSS score highlights its potential severity if exploited. The most probable attack vector is delivery of malicious content or a compromised plugin that triggers the Gtk widget, causing the use‑after‑free and leading to arbitrary code execution or a crash. Successful exploitation would grant the attacker code execution rights within the user’s session, or potentially higher privileges if privilege escalation paths exist. The exploitability requires that the client application parse the malicious content; no special operating‑system or privilege prerequisites are indicated in the advisories.

Generated by OpenCVE AI on September 20, 2026 at 16:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to the latest release (156 or newer) or to the ESR 153.3 release line.
  • Upgrade Thunderbird to the latest release (156 or newer).
  • Ensure that the latest secure versions of all Gtk libraries are installed, as the flaw affects the Gtk component – keeping system libraries up to date mitigates related issues and reduces overall attack surface.

Generated by OpenCVE AI on September 20, 2026 at 16:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-364
References
Metrics threat_severity

None

cvssV3_1

{'score': 3.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N'}

threat_severity

Low


Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156. Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.
References

Wed, 16 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3. Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
References

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 15 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Widget: Gtk component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
Title Use-after-free in the Widget: Gtk component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-20T00:22:52.980Z

Reserved: 2026-09-15T12:34:28.433Z

Link: CVE-2026-92067

cve-icon Vulnrichment

Updated: 2026-09-20T00:22:41.243Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T13:17:01.403

Modified: 2026-10-05T19:42:12.123

Link: CVE-2026-92067

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-15T12:34:28Z

Links: CVE-2026-92067 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T17:00:13Z

Weaknesses