Description
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in Firefox’s JavaScript: WebAssembly component. The engine frees an object prematurely while still maintaining a reference to it, which can corrupt data or allow arbitrary code execution. This weakness corresponds to CWE‑416. The flaw can compromise either user data or the integrity of the browser process if successfully exploited.

Affected Systems

Mozilla Firefox versions older than 154 are vulnerable, as are the ESR releases 140.14 and 153.1. All newer releases contain the fix.

Risk and Exploitability

The official CVSS score is not provided, and no EPSS value is available, but use‑after‑free bugs in web browsers routinely carry a high severity rating and can be abused via crafted JavaScript or WebAssembly modules from an attacker‑controlled site. The vulnerability is not listed in the CISA KEV catalog, and no public exploit references have been reported, yet the potential impact justifies prompt remediation.

Generated by OpenCVE AI on August 18, 2026 at 14:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or newer, or to ESR 140.14 or ESR 153.1+
  • If an upgrade cannot be performed immediately, block or disable WebAssembly in the browser so that the vulnerable component cannot run
  • Ensure the browser receives regular security updates from Mozilla or your operating system distributor

Generated by OpenCVE AI on August 18, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Use-after-free in the JavaScript: WebAssembly component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:27.882Z

Reserved: 2026-08-17T11:57:29.210Z

Link: CVE-2026-74936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:29.850

Modified: 2026-08-18T14:49:11.260

Link: CVE-2026-74936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:15:07Z

Weaknesses

No weakness.