CVE-2022-1802: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 26.7% chance of exploitation in the next 30 days.
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.
Affected products
- Mozilla Firefox: before 100.0.2 (fixed in 100.0.2); before 100.3.0 (fixed in 100.3.0)
- Mozilla Firefox ESR: before 91.9.1 (fixed in 91.9.1)
- Mozilla Thunderbird: before 91.9.1 (fixed in 91.9.1)
Published 2022-12-22. Last modified 2026-06-17.