Sceawere
Vulnerability Detail
CVE-2026-100779UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Firefox XSLT Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T13:17:42.690Z",
"pubdate": "2026-09-29T13:17:42.690Z",
"executiveSummary": "A use-after-free vulnerability has been identified within the XSLT (Extensible Stylesheet Language Transformations) component of the Mozilla Firefox browser.\nThis flaw involves improper memory management where a pointer to an object persists after the memory has been deallocated.\nThe vulnerability affects multiple release channels, specifically Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nAn unauthenticated, remote attacker could potentially exploit this memory corruption to achieve arbitrary code execution by enticing a user to process a maliciously crafted XSLT document.\nSuccessful exploitation compromises the integrity, confidentiality, and availability of the user's system by bypassing standard browser security sandboxing mechanisms.\nThe severity of this issue is high, as memory corruption vulnerabilities in browser rendering engines are frequently leveraged for remote code execution (RCE) chains.",
"technicalDetails": "The root cause of this vulnerability is a use-after-free (UAF) condition located within the XSLT processing logic. In memory-unsafe languages, a UAF occurs when an application continues to use a pointer after the memory it references has been explicitly freed via a deallocation function (such as free() or delete).\nThe exploitation flow typically begins when a threat actor serves a specially crafted XSLT style sheet to the browser. As the XSLT engine parses the XML/XSLT document, it triggers a specific sequence of operations that leads to the premature destruction of an object while a dangling pointer remains active in the engine's internal state management.\nWhen the engine subsequently attempts to reference this dangling pointer, it accesses memory that may have been repurposed for other objects or data structures by the browser's heap allocator. By controlling the content of the reallocated memory (a technique often referred to as 'heap grooming' or 'heap spraying'), an attacker can influence the browser to execute arbitrary instructions.\nThis process effectively transitions the vulnerability from a localized memory access error into a controlled execution primitive. If the attacker succeeds in overwriting a function pointer or a virtual method table (vtable) within the compromised memory block, they can redirect the execution flow to a payload of their choosing, such as a Return-Oriented Programming (ROP) chain, to bypass Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).\nThe vulnerable component is identified as the XSLT processing engine within the Firefox rendering pipeline. Affected versions include Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Exploitation requires no specific authentication, but does necessitate the victim interacting with the malicious content, such as navigating to a web page containing the trigger document. Once triggered, the attacker gains the execution privileges of the browser process, which can lead to further system compromise."
}