Use-After-Free Vulnerability in Firefox and Firefox ESR
CVE-2026-0885

6.5MEDIUM

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
13 January 2026

What is CVE-2026-0885?

A use-after-free vulnerability in the JavaScript garbage collection component of Firefox can lead to potential code execution. This issue affects versions of Firefox prior to 147 and Firefox ESR versions below 140.7, making it a critical concern for users. Proper memory management failure allows malicious actors to exploit this flaw, which may lead to unpredictable behavior, including application crashes and security breaches. Updating to the latest versions is strongly recommended to mitigate associated risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Firefox < 147

Firefox ESR < 140.7

Thunderbird < 147

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Irvan Kurniawan
.