Description
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug exists in the Layout: Text and Fonts component of Mozilla Firefox. Based on the description, the flaw allows a freed memory object to be accessed again, which may enable a malicious webpage to read or modify that memory. This could cause browser crashes or, in vulnerable builds, arbitrary code execution under the user’s privileges, affecting confidentiality, integrity, and availability.

Affected Systems

The vulnerability affects all Mozilla Firefox releases prior to Firefox 154, including Firefox ESR 115.39, ESR 140.14, and ESR 153.1. Users running any of these versions are at risk until they upgrade to a patched release. The same applies to Thunderbird releases prior to Thunderbird 154, ESR 140.14, and ESR 153.1.

Risk and Exploitability

Despite the EPSS score being below 1% and the vulnerability not being listed in CISA KEV, the use‑after‑free flaw carries a high‑severity exploitation vector that could be leveraged for remote code execution if an attacker can drive a victim to load a specially crafted web page. The CVSS score is 8.8. The lack of publicly reported exploits does not mitigate the inherent risk of the vulnerability, which permits arbitrary memory manipulation and control flow hijacking.

Generated by OpenCVE AI on August 21, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 154 or later ESR releases (115.39+, 140.14+, 153.1+).
  • Upgrade to Thunderbird 154 or later ESR releases (140.14+, 153.1+).
  • Enable automatic updates in the browser configuration to receive forthcoming security patches promptly.
  • Monitor system logs for anomalous memory access patterns or browser crashes that could indicate an exploitation attempt.

Generated by OpenCVE AI on August 21, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4750-1 firefox-esr security update
Debian DLA Debian DLA DLA-4754-1 thunderbird security update
Debian DSA Debian DSA DSA-6451-1 firefox-esr security update
Debian DSA Debian DSA DSA-6461-1 thunderbird security update
History

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla thunderbird
Weaknesses CWE-416
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla thunderbird

Wed, 19 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-359
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

threat_severity

Moderate


Tue, 18 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1. Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
References

Tue, 18 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-366

Tue, 18 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 18 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, and Firefox ESR 153.1.
Title Use-after-free in the Layout: Text and Fonts component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-08-19T17:12:38.897Z

Reserved: 2026-08-17T11:58:42.345Z

Link: CVE-2026-74969

cve-icon Vulnrichment

Updated: 2026-08-19T13:01:14.854Z

cve-icon NVD

Status : Modified

Published: 2026-08-18T13:17:34.317

Modified: 2026-08-19T17:21:12.120

Link: CVE-2026-74969

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-18T12:23:33Z

Links: CVE-2026-74969 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T17:30:04Z

Weaknesses
  • CWE-359

    Exposure of Private Personal Information to an Unauthorized Actor

  • CWE-366

    Race Condition within a Thread

  • CWE-416

    Use After Free

  • CWE-825

    Expired Pointer Dereference