CVE-2026-92040: Use-after-free in the JavaScript: WebAssembly component
Published Sep 15, 2026
·Updated
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156.
Affected Software
1 affected component
Mozilla Firefox
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 156
Event History
Sep 15, 2026
CVE Published
via MITRE·12:34 PM
Data Sourced
via MITRE·12:34 PM
Description
Frequently Asked Questions
1
Which Firefox versions contain the fix?
The vulnerability was fixed in Firefox 156. The provided information does not identify the first affected version or any affected ESR releases.