Use-After-Free Vulnerability in Mozilla Firefox JavaScript Engine
CVE-2026-2764
Key Information:
- Vendor
Mozilla
- Status
- Vendor
- CVE Published:
- 24 February 2026
Badges
What is CVE-2026-2764?
This vulnerability is identified as an issue in the JavaScript Engine of Mozilla Firefox, specifically within the JIT (Just-In-Time) compilation process. It allows attackers to exploit a use-after-free condition, potentially enabling arbitrary code execution. The flaw impacts various versions of Firefox and its Extended Support Release (ESR), making it crucial for users to upgrade to the latest versions to mitigate any associated risks.
Affected Version(s)
Firefox 115.33
Firefox 140.8
Firefox 148
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved