MFSA2022-09 Firefox: Security Vulnerabilities fixed in Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0 (CVE-2022-26485)
Description
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.
Solution(s)
mozilla-firefox-esr-upgrade-91_6_1mozilla-firefox-upgrade-97_0_2
Referenceshttps://attackerkb.com/topics/cve-2022-26485CVE - 2022-26485http://www.mozilla.org/security/announce/2022/mfsa2022-09.html