Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug in the DOM core and HTML rendering components of Mozilla Firefox can corrupt memory used by the browser process. If an attacker manages to trigger the freed memory region, they could execute arbitrary code or crash the browser, compromising the system that owns the process. The weakness is a classic use‑after‑free flaw, identified as CWE‑416.

Affected Systems

All Firefox releases prior to 154, including all Firefox ESR releases older than 140.14 and 153.1, are affected. Users running any of these versions should be aware that they are vulnerable until they update to a fixed build.

Risk and Exploitability

The CVE does not list an EPSS score or a KEV status, indicating that no publicly known exploit is tracked in those databases. However, the high confidence that the flaw can lead to memory corruption means that the risk of exploitation is significant, especially when a malicious webpage is rendered. The likely attack vector is via malicious or compromised web content that the user could encounter during normal browsing. Given the absence of mitigating controls in the affected releases, the overall risk remains high. A security assessment should consider that any user who visits untrusted sites could be exposed to this vulnerability.

Generated by OpenCVE AI on August 18, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Firefox release (version 154 or newer) or an ESR build newer than 153.1 or 140.14 to remove the use‑after‑free bug.
  • Enable Firefox’s automatic update feature so future patches are applied without manual intervention.
  • Increase the browser’s security setting to ‘Strict’ or enable the Protected Content and Safe Browsing features to minimise the impact of any unpatched content until an update can be applied.

Generated by OpenCVE AI on August 18, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Weaknesses CWE-416
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Use-after-free in the DOM: Core & HTML component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-18T12:23:29.582Z

Reserved: 2026-08-17T11:57:46.693Z

Link: CVE-2026-74944

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T13:17:30.983

Modified: 2026-08-18T13:17:30.983

Link: CVE-2026-74944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T13:30:13Z

Weaknesses