Use-After-Free in JavaScript Component of Firefox by Mozilla
CVE-2026-100796

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100796?

A use-after-free vulnerability exists in the JavaScript component of Firefox's WebAssembly, allowing attackers to exploit freed memory blocks. This can potentially lead to arbitrary code execution or information disclosure. Mozilla has addressed this issue in Firefox version 157, emphasizing the importance of keeping software updated to mitigate security risks.

Affected Version(s)

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

SecBuddyF, Tencent KeenLab (CodeBuddy Security)
.