Sceawere

Vulnerability Detail

CVE-2026-100791UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Firefox DOM Use-After-Free Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
12h ago
Vendor
Mozilla
Product
Firefox
Attack Type
N/A
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-09-29T13:17:44.133Z",
  "pubdate": "2026-09-29T13:17:44.133Z",
  "executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the Document Object Model (DOM) Core and HTML components of the Mozilla Firefox browser.\nThis vulnerability allows a remote attacker to trigger memory corruption by manipulating DOM objects, potentially leading to arbitrary code execution or browser process compromise.\nThe flaw affects multiple branches of Firefox, specifically Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nSuccessful exploitation requires an attacker to lure a user into interacting with maliciously crafted web content, such as a compromised or attacker-controlled website.\nThe risk implication is high, as UAF vulnerabilities are frequently leveraged to bypass security boundaries (sandbox escape) or execute payloads within the context of the browser process.\nNo authentication is required for an attacker to initiate the exploit sequence; the primary requirement is the successful rendering of malicious HTML/DOM structures within the target environment.",
  "technicalDetails": "The vulnerability originates from a memory management flaw within the DOM Core and HTML parsing components of the Firefox browser engine. A Use-After-Free condition occurs when the application continues to reference a memory address after that memory has been explicitly deallocated or freed. In the context of DOM handling, this usually manifests when complex JavaScript operations manipulate the object tree in a way that triggers an unexpected lifecycle transition for a specific DOM node or element.\nThe exploitation flow typically begins with the manipulation of the document structure, often utilizing complex event listeners, asynchronous garbage collection triggers, or specific CSS/DOM interactions that cause a lingering pointer to remain active in the browser's memory after the underlying object is destroyed. When the browser later attempts to access this 'dangling pointer,' it interacts with memory that may have already been reallocated to a different process or data structure.\nFrom an attacker's perspective, the objective is to perform a 'heap grooming' or 'heap spraying' operation to replace the freed memory block with controlled data before the dangling pointer is accessed. By carefully timing these operations, an attacker can influence the state of the application's memory when the UAF dereference occurs. If successful, this primitive can be leveraged to gain control over the instruction pointer or to read sensitive data structures, effectively overriding internal browser security checks.\nThis specific vulnerability highlights a flaw in how the Core and HTML components manage the synchronization between JavaScript execution and the underlying C++ DOM object lifecycle. Because the browser engine relies heavily on automatic memory management, any mismatch in reference counting or object lifecycle management within the DOM tree can lead to such UAF states. Without adequate mitigation, the exploitation of this memory corruption can result in the execution of arbitrary code with the privileges of the affected browser process, potentially leading to a total compromise of the user's browser session or further sandbox breakout attempts."
}
CVE-2026-100791: Firefox DOM Use-After-Free Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere