Description
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the JavaScript garbage collector of Mozilla Firefox. The vulnerability can allow an attacker to trigger the interpreter to read or execute memory that is no longer valid, potentially leading to arbitrary code execution or a denial‑of‑service condition. The CVE record states the issue was fixed in Firefox 155 and Firefox ESR 153.2, but does not provide a detailed exploitation chain; it is inferred that exploitation would require a specially crafted JavaScript payload delivered to a vulnerable user or local client.

Affected Systems

Mozilla Firefox use‑after‑free vulnerabilities affect all releases prior to version 155 for the standard build and prior to ESR 153.2 for the extended‑support channel. Any system running a vulnerable build of Firefox is impacted until a patched version is deployed.

Risk and Exploitability

The EPSS score for this flaw is not available and it is not listed in the CISA Known Exploited Vulnerabilities catalog, so the public exploitation probability is unclear. However, use‑after‑free conditions in the JavaScript engine are generally considered high‑severity CVSS‑based and can be exploited remotely via web pages, making the risk significant. The lack of a known KEV listing suggests no publicly observed exploitation yet, but the inherent nature of the flaw warrants immediate attention.

Generated by OpenCVE AI on September 1, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 155 or to ESR 153.2 or later, applying the official update released for this CVE.
  • If an upgrade cannot be applied immediately, apply a restrictive content‑security policy to block or constrain untrusted scripts and isolate the browser process wherever possible until the patch is available.
  • Continuously monitor Mozilla security advisories and any newly released patches and apply them at the earliest opportunity.

Generated by OpenCVE AI on September 1, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155 and Firefox ESR 153.2.
Title Use-after-free in the JavaScript: GC component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T15:10:08.870Z

Reserved: 2026-09-01T07:25:03.410Z

Link: CVE-2026-84118

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:05.607

Modified: 2026-09-01T13:20:05.607

Link: CVE-2026-84118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:14:57Z

Weaknesses