← Back to browse · API

CVE-2022-26486

Severity
CRITICAL
CVSS
9.6
EPSS
0.02349
Risk score
64.22
CISA KEV
Yes
PoC
No
Published
2022-12-22
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2022-31044, GHSA-H9VH-VXG7-XMHH
Products
Mozilla:Firefox, Mozilla:Firefox ESR unspecified <91.6.1, Mozilla:Firefox for Android unspecified <97.3.0, Mozilla:Firefox unspecified <97.0.2, Mozilla:Focus unspecified <97.3.0, Mozilla:Thunderbird unspecified <91.6.2
Sources
cisa.gov CVE-2022-26486
euvd EUVD-2022-31044

Description

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

References