Sceawere
Vulnerability Detail
CVE-2026-100784UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in Layout Component
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T13:17:43.357Z",
"pubdate": "2026-09-29T13:17:43.357Z",
"executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the Text and Fonts layout component of the Firefox browser. This memory corruption flaw permits an attacker to manipulate the lifecycle of heap-allocated objects, potentially leading to arbitrary code execution or unexpected browser termination.\nThe vulnerability affects multiple versions of the Firefox ecosystem, including Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. The primary risk involves the compromise of the renderer process, which could allow a remote attacker to achieve code execution on the host machine if memory exploitation techniques are successfully applied.\nThe vulnerability requires no specific authentication, though successful exploitation typically necessitates a user interacting with malicious web content that triggers the flawed code path within the layout engine. By carefully crafting font or text rendering parameters, an attacker may be able to force a state where the engine references memory that has already been deallocated, facilitating control over the application's execution flow.",
"technicalDetails": "The vulnerability is localized within the Layout: Text and Fonts component of the browser engine. The root cause is a Use-After-Free (UAF) condition stemming from improper management of object lifecycles during the complex text rendering and font shaping process. In the browser engine architecture, font metrics, glyph caches, and text layout data are frequently accessed and freed by the layout subsystem.\nThe flaw occurs when an object—likely related to font metrics or text style nodes—is freed, but a reference to that object remains in active use or is re-added to a work queue by the layout engine. When the engine attempts to access this dangling pointer, it performs a memory operation on freed heap space. This creates an exploitable primitive for an attacker capable of manipulating the heap state.\nThe attack flow typically follows this sequence: First, the attacker triggers the vulnerability by serving a maliciously crafted document—such as an HTML file with specific CSS directives or embedded fonts—that initiates a layout operation. The browser’s layout engine processes the text/font elements and erroneously frees memory that is still being tracked by another part of the rendering logic. Second, the attacker uses techniques such as heap spraying or controlled memory grooming to place attacker-controlled data into the recently deallocated memory slot. Third, when the engine attempts to use the original pointer, it instead interacts with the attacker's data. If the pointer is used for a function call, a virtual method table (vtable) override can be used to redirect the instruction pointer (EIP/RIP) to arbitrary code or a Return-Oriented Programming (ROP) chain.\nBecause the renderer process is responsible for parsing untrusted web content, the exploit occurs within that sandbox. If successful, this can lead to full process compromise, potentially allowing an attacker to escape the sandbox or exfiltrate sensitive data. The vulnerability is triggered automatically as part of the browser's normal rendering pipeline, requiring no user-authenticated session. The impact is severe due to the potential for reliable remote code execution (RCE) in a context where user interactions often involve navigating to untrusted domains."
}