Use-After-Free Vulnerability in Mozilla Firefox and ESR Products
CVE-2026-100791

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100791?

A use-after-free vulnerability exists in the DOM handling of Mozilla Firefox and its Extended Support Release (ESR) versions. This flaw can potentially allow attackers to exploit the browser’s memory management leading to security risks. The affected versions of Firefox are vulnerable and have received updates that fix this critical issue, ensuring improved security for users. Users are strongly advised to update to the latest versions to mitigate these risks.

Affected Version(s)

Firefox 115.42

Firefox 140.17

Firefox 153.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.