Use-After-Free Vulnerability in Firefox's Gtk Component
CVE-2026-92067

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-92067?

A use-after-free vulnerability has been identified in the Gtk component of Firefox, potentially allowing an attacker to exploit memory corruption issues. This flaw can lead to unexpected behavior in the application, possibly enabling the execution of arbitrary code or causing a crash. The vulnerability has been addressed in Firefox version 156 and Firefox ESR 153.3, where developers implemented necessary patches to mitigate the risk.

Affected Version(s)

Firefox 153.3

Firefox 156

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.