CVE-2022-28281: High severity firefox esr vulnerability
If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-28281?
CVE-2022-28281 is a vulnerability that can lead to memory corruption and a potentially exploitable crash in Mozilla Firefox, Firefox ESR, and Thunderbird.
What is the severity of CVE-2022-28281?
The severity of CVE-2022-28281 is high, with a severity value of 7.
How does CVE-2022-28281 occur?
CVE-2022-28281 occurs when a compromised content process sends an unexpected number of WebAuthN Extensions in a Register command to the parent process.
Which software versions are affected by CVE-2022-28281?
CVE-2022-28281 affects Mozilla Firefox ESR versions up to but excluding 91.8, Mozilla Firefox versions up to but excluding 99, and Mozilla Thunderbird versions up to but excluding 91.8.
How can I fix CVE-2022-28281?
To fix CVE-2022-28281, update your Mozilla Firefox, Firefox ESR, or Thunderbird to the latest version available from Mozilla.