Description
Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic use‑after‑free in the graphics text rendering subsystem of Mozilla Firefox. A use‑after‑free can corrupt memory during text rendering, and while the CVE description does not explicitly state the available impact, such a flaw can potentially lead to crashes or, in severe cases, execution of arbitrary code within the browser process.

Affected Systems

Mozilla Firefox browsers, including both stable and ESR branches, are affected. All versions prior to Firefox 154, ESR 115.39, ESR 140.14, or ESR 153.1 are vulnerable, as the fix was applied only in those releases and newer ones.

Risk and Exploitability

No EPSS score is available and the CVE is not listed in the CISA KEV catalog, so the exact probability of exploitation is unclear. A use‑after‑free flaw in a graphics component can usually be triggered by rendering malicious content from a webpage, which is inferred from the component’s role; however, exploitation would require the browser to process the offending content. The potential impact is high if the flaw is successfully leveraged.

Generated by OpenCVE AI on August 18, 2026 at 14:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox 154 or newer, or the latest ESR release (115.39, 140.14, or 153.1) that contains the fix.
  • Restart the browser after updating to ensure the new binary is running.
  • If an immediate update is not possible, consider using a different browser or running Firefox in a sandboxed environment until the patch is applied.

Generated by OpenCVE AI on August 18, 2026 at 14:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Use-after-free in the Graphics: Text component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:28.488Z

Reserved: 2026-08-17T11:57:37.997Z

Link: CVE-2026-74940

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T13:17:30.370

Modified: 2026-08-18T14:49:11.260

Link: CVE-2026-74940

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T15:15:03Z

Weaknesses