Use-After-Free Vulnerability in Firefox and Firefox ESR Products
CVE-2026-8947

7.3HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
19 May 2026

What is CVE-2026-8947?

A use-after-free vulnerability exists in the DOM: Bindings (WebIDL) component of Firefox, which can potentially allow an attacker to execute arbitrary code. This issue can be triggered when certain objects are freed and subsequently accessed, leading to unexpected behavior. Mozilla has addressed this vulnerability in updates to Firefox 151 and Firefox ESR versions 115.36 and 140.11, emphasizing the importance of applying the latest security patches to mitigate risks.

Affected Version(s)

Firefox 115.36

Firefox 140.11

Firefox 151

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Satoki Tsuji
.