Sceawere
Vulnerability Detail
CVE-2026-100778UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Firefox DOM Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-29T13:17:42.577Z",
"pubdate": "2026-09-29T13:17:42.577Z",
"executiveSummary": "This vulnerability is identified as a Use-After-Free (UAF) flaw residing within the Core and HTML components of the Mozilla Firefox browser. A UAF vulnerability occurs when an application continues to use a memory pointer after the associated memory has been deallocated, leading to undefined behavior. In the context of browser security, this flaw facilitates a sandbox escape, allowing an attacker to bypass the browser's security boundary and execute arbitrary code with elevated privileges.\nThe vulnerability affects multiple versions of Firefox, specifically Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. The primary risk associated with this flaw is potential system compromise, as it allows attackers to escape the restricted sandbox environment, potentially leading to unauthorized data access, arbitrary code execution, or system takeover depending on the context of the running process. Exploitation generally requires the victim to interact with malicious web content that triggers the flawed DOM manipulation logic. Successful exploitation grants the attacker capabilities equivalent to the browser process or potentially higher, depending on the system architecture and existing security controls.",
"technicalDetails": "The root cause of this vulnerability lies in the memory management lifecycle of the DOM (Document Object Model) within the Core and HTML components of the Firefox browser engine. Specifically, it involves an incorrect synchronization of object lifetimes where a reference to a heap-allocated object is retained after the object has been explicitly freed via the browser's memory management routines.\nThe attack flow typically begins with an attacker hosting a specially crafted webpage containing malicious JavaScript designed to manipulate the DOM in a way that creates a 'dangling pointer.' By triggering specific asynchronous events or DOM mutations—such as rapid insertion, deletion, or modification of elements—the attacker forces the browser to free an object that still has active, lingering references in the execution context.\nOnce the memory has been deallocated, the attacker performs a 'heap grooming' or 'heap spraying' technique to reallocate the freed memory block with attacker-controlled data. When the browser subsequently attempts to access the original pointer, it instead operates on the attacker's injected data. This redirection allows the attacker to hijack the control flow of the browser execution thread.\nBecause this vulnerability occurs within the browser's Core and HTML processing modules, it specifically facilitates a sandbox escape. By controlling the execution flow, the attacker can bypass the restricted browser process sandbox, which is intended to isolate web content from the underlying host operating system. This transition allows for arbitrary code execution in the context of the user, bypassing security policy enforcement mechanisms.\nThe vulnerability is agnostic to user authentication; it is triggered automatically when a victim renders the malicious content. No specific user interaction beyond navigating to the site is strictly required. The impact after the sandbox escape allows the attacker to potentially install malware, intercept sensitive user data, or persist within the host system. This vulnerability has been addressed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17 through corrected object lifetime management and improved memory safety checks within the DOM processing engine."
}