Sceawere
Vulnerability Detail
CVE-2026-100785UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in DOM Core
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T13:17:43.470Z",
"pubdate": "2026-09-29T13:17:43.470Z",
"executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the Document Object Model (DOM) Core and HTML components of the Firefox browser engine.\nThis memory corruption flaw occurs when the application attempts to access a memory address that has already been deallocated, leading to undefined behavior.\nSuccessful exploitation allows an unauthenticated, remote attacker to trigger memory corruption, which may result in arbitrary code execution (ACE) or a denial-of-service (DoS) state.\nThe vulnerability affects multiple versions, including Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nBy convincing a user to process malicious web content, an attacker can manipulate the internal state of the DOM, potentially bypassing security boundaries.\nThe risk is categorized as high, as it impacts memory safety and could be leveraged by attackers for malicious payloads in a browser context.\nMitigation requires upgrading the browser to the latest patched versions to ensure proper memory management and object lifecycle enforcement.",
"technicalDetails": "The vulnerability is a classic Use-After-Free (UAF) condition residing within the DOM Core and HTML parsing components. A UAF vulnerability is triggered when a program continues to use a pointer after the memory area it references has been freed or reallocated.\nIn the context of the Firefox DOM engine, this typically involves a race condition or a lifecycle mismanagement of internal HTML elements. When an object is garbage collected or explicitly deallocated, existing references to that object (dangling pointers) are not properly nullified. Subsequent operations on these dangling pointers lead to memory access violations.\nThe attack flow initiates when a victim is directed to a malicious website containing specially crafted HTML elements. These elements are designed to trigger specific event handlers or DOM tree manipulations that force the engine to release an object prematurely while maintaining an active reference to it.\nOnce the attacker gains a handle on the dangling pointer, they can attempt to perform heap spraying or memory grooming to occupy the freed memory address with attacker-controlled data. When the engine subsequently accesses the original, now-dangling pointer, it reads the attacker's data instead of the intended object.\nThis primitive allows an attacker to achieve control over the instruction pointer or modify object metadata, potentially leading to arbitrary code execution within the context of the browser process. If code execution is not achievable, the inconsistency in the DOM state will likely trigger a process crash, resulting in a denial-of-service.\nThe vulnerability persists in the core DOM handling routines, making it accessible via standard web content parsing. No specific authentication is required, as the vulnerability is triggered through standard browser interaction with a malicious payload. Successful exploitation hinges on the attacker's ability to reliably predict or control heap layout following the deallocation, which remains a significant risk despite modern browser mitigations like heap hardening and sandboxing.\nAffected versions include Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. The exploit impact is severe, effectively compromising the integrity of the browser process and bypassing the intended security model established by the DOM's memory management policies."
}