Sceawere
Vulnerability Detail
CVE-2026-100774UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Firefox DOM Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T13:17:41.870Z",
"pubdate": "2026-09-29T13:17:41.870Z",
"executiveSummary": "This vulnerability is a use-after-free (UAF) flaw residing within the DOM Core and HTML components of the Firefox browser. A use-after-free occurs when an application continues to use a memory pointer after the memory it references has been deallocated or freed, leading to undefined behavior.\nThe impact of this vulnerability is critical, potentially allowing an attacker to execute arbitrary code within the context of the browser process if successfully exploited. The vulnerability affects multiple versions of Firefox, specifically Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nExploitation generally requires the attacker to influence the browser's memory management by inducing specific DOM manipulations or interacting with malformed HTML content. By crafting a malicious web page, an attacker could trigger the UAF condition, leading to memory corruption. Successful exploitation allows for remote code execution, compromising the user's system and enabling the bypass of existing browser security controls. No authentication is required to trigger this vulnerability, as it can be exploited through standard web-based interaction with a victim.",
"technicalDetails": "The vulnerability is rooted in the improper management of object lifecycles within the Document Object Model (DOM) Core and HTML parsing components. In complex browser architectures, the DOM tree maintains various references to objects; when the lifetime of these objects is not synchronized correctly between the C++ backend and the JavaScript frontend, a stale pointer can persist after the underlying memory has been released.\nThe root cause is a race condition or an improper reference counting mechanism that fails to invalidate all pointers when a specific DOM node or HTML element is destroyed. During typical browser operation, complex HTML structures undergo dynamic modifications. If an attacker can force the browser to execute a routine that accesses a freed memory block, they can manipulate the state of the application. This involves an 'attacker-induced' sequence where the browser's Garbage Collector (GC) or a manual memory management routine prematurely frees an object that is still referenced by an active DOM element.\nThe exploitation flow typically begins with heap grooming. An attacker uses JavaScript to allocate large amounts of memory, arranging the heap layout to place objects in a predictable state. Following this, the attacker triggers the vulnerable DOM or HTML component to free the target memory. Because the application retains a 'dangling' pointer to this location, the attacker then triggers a secondary allocation that occupies the exact memory region previously held by the freed object. By filling this region with attacker-controlled data (the payload), the dangling pointer is repurposed to point to malicious data.\nWhen the browser subsequently attempts to access the original pointer—believing it still refers to a valid object—it instead interacts with the attacker's payload. In the context of browser components, this often manifests as a call to a virtual function or an access to a data structure via a pointer that has been hijacked. By controlling the vtable or the data members of the object, an attacker can hijack the program execution flow, typically redirecting it to a ROP (Return Oriented Programming) chain or shellcode, resulting in arbitrary code execution within the browser's security context.\nThe vulnerability is persistent across the affected versions until the provided patches are applied, as it involves the core memory safety logic of the browser's layout and rendering engines."
}