Use-After-Free Vulnerability in Firefox ImageLib Component
CVE-2026-74943

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
18 August 2026

Badges

πŸ“ˆ Score: 564πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-74943?

CVE-2026-74943 is a critical vulnerability in the ImageLib component of Mozilla Firefox, which is widely used as a web browser and platform for web applications. This vulnerability stems from a use-after-free error, which occurs when a program continues to use a memory allocation after it has been freed, potentially leading to unpredictable behavior. If exploited, this vulnerability could allow attackers to execute arbitrary code, compromising user security and privacy. Organizations that utilize Mozilla Firefox, especially within enterprise environments, may face significant risks if this vulnerability is not addressed. The issue has already been fixed in specific versions of Firefox, including Firefox 154 and both standard and Extended Support Release (ESR) variants.

Potential impact of CVE-2026-74943

  1. Remote Code Execution: The primary impact of CVE-2026-74943 is the risk of remote code execution. Attackers could exploit this vulnerability to run malicious code on affected systems, potentially gaining full control over the compromised device.

  2. Data Breaches: Exploitation of this vulnerability could lead to unauthorized access to sensitive data. In a corporate context, this could result in significant data breaches, exposing proprietary information and jeopardizing client confidentiality.

  3. Widespread Exploitation: With the vulnerability being actively exploited, the threat landscape becomes increasingly perilous. Cybercriminals, including potential ransomware groups, may leverage this flaw to deploy further attacks or spread malware, affecting not just individual users but entire networks and organizations.

Affected Version(s)

Firefox 115.39

Firefox 140.14

Firefox 153.1

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdulaziz Alasaiqah
.