CVE-2022-26485
Mozilla Firefox Use-After-Free Vulnerability
- Published
- Dec 22, 2022
- Updated
- Oct 21, 2025
- Assigning CNA
- mozilla
- Evidence observed
- Mar 7, 2022
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 96.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Sources
1Proof-of-concept exploit for CVE-2022-26485 targeting Firefox 78.0 on Windows, demonstrating a remote code execution vulnerability in the browser's XSLT processing.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.