CVE-2022-40957: Mozilla Firefox

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Firefox on ARM64 platforms.*. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

Affected products

  • Mozilla Firefox: before 105.0 (fixed in 105.0)
  • Mozilla Firefox ESR: before 102.3 (fixed in 102.3)
  • Mozilla Thunderbird: before 102.3 (fixed in 102.3)

Published 2022-12-22. Last modified 2026-06-17.