Sceawere
Vulnerability Detail
CVE-2026-100772UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
DOM Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T13:17:41.450Z",
"pubdate": "2026-09-29T13:17:41.450Z",
"executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the Document Object Model (DOM) Core and HTML components of the Mozilla Firefox browser. This memory corruption flaw allows an unauthenticated, remote attacker to trigger a state where the browser attempts to access a memory location that has already been deallocated.\nThe vulnerability affects Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. Successful exploitation can lead to arbitrary code execution within the context of the browser process, potential sandbox escape, or unauthorized access to sensitive user data. Exploitation typically requires the victim to interact with a specially crafted malicious web page that manipulates DOM objects to induce the dangling pointer condition.\nThe primary risk implication is a compromise of the client-side environment. By leveraging this UAF, an attacker could achieve stable memory corruption primitives, facilitating the deployment of malicious payloads. Given the nature of UAF vulnerabilities, this issue represents a significant threat to browser security and data integrity.",
"technicalDetails": "The root cause of this vulnerability is improper memory lifecycle management within the DOM Core and HTML parsing components. A Use-After-Free condition arises when a memory buffer, specifically an object associated with the DOM, is freed while a dangling pointer or reference to that memory address persists elsewhere in the application logic. If the browser subsequently attempts to access this freed memory, it can lead to undefined behavior, crash, or exploitation.\nIn the context of the Firefox DOM engine, this vulnerability likely involves complex interactions between script-driven DOM manipulation and internal object lifetime tracking. When a DOM element is removed or garbage-collected while an asynchronous process or an event listener still maintains a reference to it, the object's memory is released. If a secondary operation invokes a method or accesses a property of that now-defunct object, the engine operates on data that may have been repurposed by the memory allocator for other browser objects.\nThe exploitation flow generally proceeds through several distinct phases. Initially, the attacker triggers the creation of a specific DOM structure using JavaScript. Through carefully timed actions—such as forced garbage collection (GC), navigation, or specific event triggering—the attacker induces a state where a critical object is deallocated. Following this, the attacker performs heap spraying or memory grooming to place controlled data in the memory slot previously occupied by the freed object. Once the dangling pointer is dereferenced, the engine utilizes the attacker-controlled data as a legitimate object pointer or vtable, redirecting the execution flow.\nThis vulnerability is reachable via remote attack vectors, requiring no authentication or local privileges from the attacker beyond the capability to host or inject malicious content. The exploitation is facilitated by the browser's HTML parsing logic, which may fail to synchronize object reference counts during complex document tree modifications. Post-exploitation, an attacker can achieve arbitrary read/write primitives within the browser memory space, bypassing ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) to execute shellcode or gain control over the user's browser session. The affected versions include Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17, all of which contain the identified memory management deficiency."
}