Use-After-Free Vulnerability in Firefox JavaScript Engine by Mozilla
CVE-2026-100825

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100825?

A vulnerability exists within the JavaScript Engine's JIT component of Mozilla's Firefox browser, which allows an attacker to exploit a use-after-free condition. This can potentially lead to memory corruption and execute arbitrary code. Mozilla has addressed this issue in the latest versions, including Firefox ESR 153.4 and Firefox 157, ensuring enhanced security and stability for users. Users are advised to upgrade to these versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

x0e
.