EXPOSURES › CVE-2022-26486
CVE-2022-26486
HIGH ⌖ ON CISA KEV · EXPLOITEDMozilla Firefox contained an unpatched use-after-free vulnerability in its WebGPU IPC Framework that allowed arbitrary code execution and was actively exploited in the wild.
The vulnerability was a use-after-free flaw in Firefox's WebGPU IPC Framework enabling remote code execution. DIB organizations must ensure their browsers are patched immediately, as unpatched CVEs in actively exploited-in-wild vulnerabilities represent a severe compliance and operational risk.
Shame score — The vulnerability was actively exploited in the wild and allowed arbitrary code execution, indicating a severe and avoidable failure to patch a known, high-severity flaw.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution.