Use-After-Free Vulnerability in Firefox ESR Products by Mozilla
CVE-2026-100832

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100832?

A use-after-free vulnerability exists in the Graphics: Canvas2D component of Firefox ESR products. This flaw can lead to potential memory corruption, allowing attackers to exploit this issue to execute arbitrary code or crash the application. The vulnerability has been addressed in Firefox ESR versions 153.4, 115.42, and 140.17, which include patches to enhance security and mitigate the risks associated with this flaw.

Affected Version(s)

Firefox 115.42

Firefox 140.17

Firefox 153.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.