Use-After-Free Vulnerability in Firefox by Mozilla
CVE-2026-100815

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100815?

A use-after-free vulnerability has been identified in the CSS Parsing and Computation component of Mozilla Firefox. This flaw can potentially allow attackers to execute arbitrary code under certain conditions, creating risks for users who have not updated to the patched versions. The vulnerability was addressed with updates in Firefox ESR 153.4 and Firefox 157, highlighting the importance of regular software maintenance and prompt installation of security updates to safeguard against exploitation.

Affected Version(s)

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.