Description
Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Use‑after‑free potentially enabling remote code execution via the widget component
Action: Patch
AI Analysis

Impact

A memory corruption flaw occurs when the widget component accesses memory after it has been freed. This use‑after‑free can allow an attacker to execute arbitrary code or crash the browser, leading to loss of confidentiality, integrity, or availability.

Affected Systems

Mozilla Firefox is affected, specifically Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Users running versions older than those enumerated remain vulnerable.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable; the vulnerability is not listed in CISA KEV. The likely attack vector is through malicious web content that triggers the widget, enabling a remote attacker to exploit the use‑after‑free for code execution or denial of service.

Generated by OpenCVE AI on September 29, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 157 or a newer release, or to ESR 153.4, ESR 115.42, or ESR 140.17 which contain the patch.
  • If an update cannot be applied, disable the widget component via about:config or remove the related plugin to prevent exploitation.
  • Monitor browser behavior and logs for anomalies that could indicate exploitation attempts.

Generated by OpenCVE AI on September 29, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Widget component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Use-after-free in the Widget component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T15:19:33.386Z

Reserved: 2026-09-26T19:15:14.718Z

Link: CVE-2026-100757

cve-icon Vulnrichment

Updated: 2026-09-29T15:10:49.554Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.047

Modified: 2026-09-29T16:17:05.190

Link: CVE-2026-100757

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:00:18Z

Weaknesses