{"id":"CVE-2022-26486","title":"An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape","summary":"An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.…","severity":"critical","cvss":9.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwe":["CWE-416","CWE-416"],"vendor":"mozilla","product":"firefox","affected":["firefox < 91.6.1","firefox < 97.0.2","firefox_focus < 97.3.0","firefox_mobile < 97.3.0","thunderbird < 91.6.2"],"patched":["firefox 97.0.2","firefox_focus 97.3.0","firefox_mobile 97.3.0","thunderbird 91.6.2"],"published":"2022-12-22","updated":"2026-08-19","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-26486","references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1758070","label":"security@mozilla.org"},{"url":"https://www.mozilla.org/security/advisories/mfsa2022-09/","label":"security@mozilla.org"},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1758070","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.mozilla.org/security/advisories/mfsa2022-09/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26486","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild"],"epss":0.02349,"epssPercentile":0.82773,"kev":true,"kevDateAdded":"2022-03-07","kevDueDate":"2022-03-21","kevRansomware":false,"exploited":true,"zeroDay":true,"ingestedAt":"2026-08-19T15:41:15.262Z","slug":"CVE-2022-26486","body":"## Overview\n\nAn unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.\n\n## Affected\n\n- `firefox < 91.6.1`\n- `firefox < 97.0.2`\n- `firefox_focus < 97.3.0`\n- `firefox_mobile < 97.3.0`\n- `thunderbird < 91.6.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `firefox 97.0.2`\n- `firefox_focus 97.3.0`\n- `firefox_mobile 97.3.0`\n- `thunderbird 91.6.2`","depth":"hadal","depthScore":78,"depthScoreParts":{"impact":52.8,"likelihood":0.5,"exploitation":25,"ransomware":0},"changes":[]}