Use-After-Free Vulnerability in JavaScript Component of Firefox
CVE-2026-74937

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-74937?

A use-after-free vulnerability was identified in the JavaScript component of Firefox, which could allow an attacker to execute arbitrary code or crash the browser. This security issue was mitigated in the updated versions of Firefox 154 and Firefox ESR 153.1. Users are recommended to update their browsers to these versions to ensure protection against potential exploits.

Affected Version(s)

Firefox 153.1

Firefox 154

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Amy Burnett of OpenAI
.