Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteOn March 5, 2022, Mozilla released emergency security updates for two Firefox vulnerabilities it said were being exploited in the wild. The flaws affected XSLT parameter processing and the WebGPU inter-process communication (IPC) framework. The fixes were Firefox 97.0.2 and Firefox ESR 91.6.1, among other product builds—but those 2022 versions are obsolete. If you use Firefox now, install the latest update offered for your platform.
What Mozilla patched in March 2022
Mozilla’s MFSA 2022-09 advisory, published March 5, 2022, assigned an overall impact rating of high. It rated each of the two vulnerabilities individually as critical and said it had reports of attacks abusing both flaws.
| CVE | Affected component and trigger | Described consequence | March 2022 fixed versions |
|---|---|---|---|
| CVE-2022-26485 | XSLT parameter processing; an XSLT parameter was removed during processing. | Use-after-free. | Firefox 97.0.2; Firefox ESR 91.6.1; Firefox for Android 97.3; Firefox Focus 97.3; Thunderbird 91.6.2. Mozilla’s advisory lists these fixed products and versions. |
| CVE-2022-26486 | WebGPU IPC framework; an unexpected message was received. | Use-after-free with the potential for an exploitable sandbox escape. | Firefox 97.0.2; Firefox ESR 91.6.1; Firefox for Android 97.3; Firefox Focus 97.3; Thunderbird 91.6.2. Mozilla’s advisory lists these fixed products and versions. |
Mozilla used the same wording for each vulnerability: “We have had reports of attacks in the wild abusing this flaw.” It credited Wang Gang, Liu Jialei, Du Sihang, Huang Yi, and Yang Kang of 360 ATA with reporting both issues.
What the exploitation reports establish—and what they do not
Mozilla’s notice confirms reports of real-world attacks exploiting each vulnerability. It does not identify the attackers, victims, campaign, geographic scope, number of attacks, or a complete exploit chain. The sandbox-escape potential described for CVE-2022-26486 should not be read as proof that every attack achieved code execution or escaped the sandbox.
#1 Best Overall
How to update Firefox now
The 97.0.2 and ESR 91.6.1 builds fixed these specific issues in March 2022; they are not current update targets. Mozilla’s Firefox update instructions direct users to obtain the latest update through Firefox or the platform that provides it.
- Manually installed desktop Firefox: Open the menu and select Help > About Firefox. Let Firefox check for and download updates, then restart the browser if prompted to apply one.
- Linux distribution package: Update Firefox through your distribution’s package repository.
- Microsoft Store installation: Get Firefox updates through the Microsoft Store.
- Managed work or school installation: Follow your organization’s approved update process.
Mozilla says Firefox updates automatically in most cases. Its security advisory index lists later releases, underscoring why the March 2022 version numbers should not be used as present-day guidance.
Quick Recap
Rank #4
Rank #3
Rank #2
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

