Sceawere
Vulnerability Detail
CVE-2026-100790UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Firefox XSLT Use-After-Free Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T13:17:44.030Z",
"pubdate": "2026-09-29T13:17:44.030Z",
"executiveSummary": "A use-after-free (UAF) vulnerability exists within the XSLT (Extensible Stylesheet Language Transformations) component of the Firefox browser engine.\nThe vulnerability allows a remote attacker to trigger a memory corruption condition by manipulating specific XSLT objects during the transformation process.\nSuccessful exploitation of this flaw can result in arbitrary code execution, privilege escalation, or unauthorized access to sensitive memory contents within the context of the browser process.\nAffected products include Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nThe risk is critical as it potentially enables a threat actor to compromise the host system through maliciously crafted web content.\nExploitation typically requires the victim to navigate to a site containing specially designed XSLT style sheets, requiring minimal user interaction beyond the initial browser session.\nThis vulnerability highlights a flaw in memory management practices within the browser's document rendering subsystem, necessitating immediate remediation via update deployment.",
"technicalDetails": "The root cause of this vulnerability is a use-after-free condition originating in the XSLT processing logic. In the context of browser rendering engines, XSLT transformations involve complex memory management for node trees and stylesheets. The vulnerability occurs when the engine improperly manages the lifecycle of an object during a transformation, leading to a dangling pointer.\nThe attack flow begins when an attacker embeds a malicious XSLT stylesheet within an XML or HTML document. As the Firefox rendering engine attempts to parse and apply the XSLT transformation, specific operations induce a race condition or an object-releasing sequence that leaves a pointer to a deallocated memory address active.\nSubsequent access to this dangling pointer allows for a secondary operation—often an object replacement—where the attacker replaces the freed memory block with controlled data. When the engine eventually attempts to invoke a virtual method or access a member variable on the pointer, it operates on data provided by the attacker.\nExploitation techniques generally leverage heap spraying or controlled memory grooming to increase the reliability of object replacement within the heap layout. By placing specific data at the memory address previously occupied by the freed object, the attacker can hijack control flow, typically redirecting execution to malicious shellcode or a Return-Oriented Programming (ROP) chain to bypass memory protections like DEP (Data Execution Prevention) and ASLR (Address Space Layout Randomization).\nThe vulnerability is localized to the XSLT parsing and execution component. Because XSLT processing is a standard capability of the browser's document engine, the attack is triggered over the network without requiring prior authentication. The execution context is bound to the browser's rendering process, which often operates with low privileges, but further exploitation chains can lead to sandbox escapes or information disclosure if combined with other browser vulnerabilities.\nGiven the nature of use-after-free, the severity is high as it undermines the core memory integrity of the Firefox engine. The affected versions (Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17) reflect the specific patch rollout periods required to fix the dangling pointer state and ensure robust object lifecycle management."
}