Use-After-Free Vulnerability in Firefox and Firefox ESR
CVE-2026-0885
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 13 January 2026
What is CVE-2026-0885?
A use-after-free vulnerability in the JavaScript garbage collection component of Firefox can lead to potential code execution. This issue affects versions of Firefox prior to 147 and Firefox ESR versions below 140.7, making it a critical concern for users. Proper memory management failure allows malicious actors to exploit this flaw, which may lead to unpredictable behavior, including application crashes and security breaches. Updating to the latest versions is strongly recommended to mitigate associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Firefox < 147
Firefox ESR < 140.7
Thunderbird < 147
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved