Sceawere

Vulnerability Detail

CVE-2026-100780UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Use-After-Free in DOM Core

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
12h ago
Vendor
Mozilla
Product
Firefox
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-29T13:17:42.900Z",
  "pubdate": "2026-09-29T13:17:42.900Z",
  "executiveSummary": "A critical Use-After-Free (UAF) vulnerability has been identified within the DOM: Core & HTML components of Mozilla Firefox.\nThis memory corruption flaw allows a remote attacker to trigger an invalid memory access, potentially leading to arbitrary code execution or a denial-of-service state.\nThe vulnerability resides in how the browser handles the lifecycle of DOM objects, where memory is accessed after being deallocated.\nAffected software versions include Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nExploitation generally requires a user to navigate to a maliciously crafted webpage, which manipulates the browser's document object model to trigger the flawed state.\nSuccessful exploitation compromises the integrity and confidentiality of the browser session and could allow for a sandbox escape, posing a significant risk to end-users.\nThe flaw necessitates immediate updates to the browser software to ensure the underlying memory management logic is patched.",
  "technicalDetails": "The vulnerability is classified as a Use-After-Free (UAF), a type of memory corruption flaw occurring when an application continues to use a pointer after the memory it references has been explicitly freed.\nIn the context of the Firefox DOM: Core & HTML implementation, the defect arises from improper management of object lifecycles during complex document manipulation.\nThe root cause involves a race condition or an incorrect reference counting mechanism where a DOM node or HTML element is deallocated while a persistent pointer or reference to that object remains active in the DOM tree or an event handler queue.\nAttack flow typically begins when a threat actor creates a specifically engineered HTML document that utilizes JavaScript to manipulate the DOM in a way that forces a specific object into a stale state while simultaneously triggering an action that accesses the object.\nStep-by-step exploitation involves: 1) Initializing a targeted DOM structure; 2) Inducing a garbage collection or manual object deletion cycle while holding a dangling reference; 3) Reallocating memory at the address previously occupied by the freed object to control its data content (often via Heap Spraying or primitive allocation); 4) Triggering the use of the dangling pointer, which now points to attacker-controlled data.\nBy manipulating the object's vtable or internal state stored at the reallocated memory location, an attacker can hijack the control flow of the browser process.\nIf the attacker achieves control over the execution flow, they may bypass security boundaries, potentially executing arbitrary machine code with the privileges of the Firefox content process.\nThe vulnerability is exposed via the web content rendering engine, meaning the threat is present whenever the browser renders untrusted content, requiring no specific authentication from the user beyond interacting with the malicious page.\nPost-exploitation activities are limited by the browser's sandbox environment, but a sophisticated attacker may leverage this UAF as part of a chain to escape the sandbox or exfiltrate sensitive data from the user's session."
}
CVE-2026-100780: Use-After-Free in DOM Core (HIGH Severity, CVSS: 8.8) | Sceawere