QID 630848

Date Published: 2023-03-03

QID 630848: Firefox For Android Use After Free Vulnerability

An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox less than 97.3.0

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Critical - 9.6 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to CVE-2022-26486 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630848

    Software Advisories
    Advisory ID Software Component Link
    CVE-2022-26486 Android URL Logo nvd.nist.gov/vuln/detail/CVE-2022-26486