Executive brief
A vulnerability has been identified in the Disability Access APIs of the Firefox web browser. This component is responsible for providing accessibility features to users with disabilities. An exploit could allow a malicious website to break out of the browser's security sandbox, potentially gaining unauthorized access to the underlying operating system or user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Disability Access APIs component of Mozilla Firefox. The flaw occurs when the browser attempts to access memory that has already been freed, which can be triggered by a malicious actor through a specially crafted web page. This memory corruption can be leveraged to achieve a sandbox escape, allowing code execution outside of the restricted browser process. The vulnerability is reachable via the network (web browsing) and requires no special privileges. Mozilla has addressed this issue in Firefox 153 and ESR versions 115.38 and 140.13.
Affected products
- Mozilla Firefox Before 153
- Mozilla Firefox ESR Before 115.38, Before 140.13
Timeline
- 2026-07-21: advisory
- 2026-07-21: patched