Description
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2.
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the DOM: Core & HTML component of Mozilla Firefox. It occurs when the browser frees an object in the Document Object Model and later accesses it again, leading to memory corruption. This flaw can potentially crash the browser or allow an attacker to execute arbitrary code in the context of the page. The weakness corresponds to CWE‑416.

Affected Systems

The affected product is Mozilla Firefox. Versions before 155, and older ESR releases before 140.15 and 153.2, contain the flaw. Users running these releases are vulnerable.

Risk and Exploitability

While the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the nature of the use‑after‑free error implies a high potential for remote exploitation. The likely attack vector is a malicious web page that causes the browser to free an object and then reuse it. Because no public workaround exists, the safest mitigation is to upgrade to a fixed release.

Generated by OpenCVE AI on September 1, 2026 at 13:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox 155 or newer ESR 140.15/153.2 releases.
  • Configure a strict Content Security Policy that blocks inline scripts and restricts data URIs to reduce the opportunity for exploitation.
  • Use a reputable security extension such as NoScript, uBlock Origin, or another content‑blocking tool to limit script execution until the update is applied.

Generated by OpenCVE AI on September 1, 2026 at 13:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 01 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, and Firefox ESR 153.2.
Title Use-after-free in the DOM: Core & HTML component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-01T15:01:02.218Z

Reserved: 2026-09-01T07:25:18.000Z

Link: CVE-2026-84124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T13:20:06.290

Modified: 2026-09-01T15:17:42.557

Link: CVE-2026-84124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:14:56Z

Weaknesses