Executive brief
A security vulnerability has been identified in Mozilla Firefox's Disability Access APIs, which are used to support assistive technologies like screen readers. An attacker could exploit this flaw to bypass the browser's security sandbox, which is designed to keep malicious web content isolated from the rest of the computer. If successfully exploited, this could allow a malicious website to gain unauthorized access to the underlying operating system or user data.
Technical details
A use-after-free vulnerability exists in the Disability Access APIs component of Mozilla Firefox. The flaw occurs when the browser continues to use a memory pointer after it has been freed, leading to memory corruption. A remote attacker can exploit this by enticing a user to visit a specially crafted website, potentially leading to a sandbox escape. This would allow the attacker to execute code outside of the restricted browser environment. The issue is resolved in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Affected products
- Mozilla Firefox < 153
- Mozilla Firefox ESR < 115.38, < 140.13
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched