CVE-2018-12292: Palemoon Pale Moon

Critical severity, CVSS 9.8. EPSS: 9.1% chance of exploitation in the next 30 days.

A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.

Affected products

  • Palemoon Pale Moon: before 27.9.3 (fixed in 27.9.3)

Published 2018-06-13. Last modified 2026-06-17.