Description
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Published: 2026-09-29
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

A use‑after‑free flaw exists in the JavaScript WebAssembly engine that may allow an attacker to corrupt memory and potentially execute arbitrary code. The vulnerability originates from a race when an object is freed and reused, enabling a malicious script to craft a WebAssembly module that triggers the invalid memory reference. Successful exploitation could compromise the confidentiality, integrity, and availability of the user’s system by allowing code execution within the browser context.

Affected Systems

The flaw affects Mozilla Firefox browsers prior to the release of ESR 153.4 and the standard Firefox build 157. Users running earlier ESR or non‑ESR versions of Firefox are potentially vulnerable. The vulnerability is specific to the WebAssembly component of the JavaScript engine and does not affect other components or products beyond Firefox.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, so the exact exploit likelihood is uncertain from the supplied data. However, because the issue involves a use‑after‑free in a browser feature widely used for web content, web pages delivering malicious WebAssembly modules could serve as a vector. The vulnerability is not yet listed in CISA’s KEV catalog, indicating no known widespread exploitation. The attack vector is likely remote via carefully crafted web content, and it requires an active user to open a tainted page. While the severity is potentially high, the lack of publicly disclosed exploits and absence from KEV suggest a moderate risk until further proof of concept becomes available.

Generated by OpenCVE AI on September 29, 2026 at 15:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox ESR 153.4 or later to receive the WebAssembly engine fix.
  • Upgrade to the latest stable Firefox release, which includes the same fix as of version 157 or newer.
  • Disable WebAssembly in Firefox until a patch is applied, for example by setting `javascript.options.wasm` to `0` in about:config.

Generated by OpenCVE AI on September 29, 2026 at 15:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Title Use-after-free in the JavaScript: WebAssembly component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T14:49:16.347Z

Reserved: 2026-09-26T19:15:21.913Z

Link: CVE-2026-100765

cve-icon Vulnrichment

Updated: 2026-09-29T14:43:07.925Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.730

Modified: 2026-09-29T15:17:12.463

Link: CVE-2026-100765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:00:16Z

Weaknesses