Executive brief
A security vulnerability exists in the Firefox web browser's layout engine, specifically affecting how it handles scrolling and overlapping content. If a user visits a specially crafted website, the browser could crash or allow an attacker to execute unauthorized code. This could lead to the theft of sensitive information or a complete compromise of the user's computer.
Technical details
A use-after-free vulnerability exists in the 'Layout: Scrolling and Overflow' component of Mozilla Firefox. The issue is rooted in the 'mozilla::DisplayPortUtils::ShouldAsyncScrollWithAnchor' function, where a reference to a hashtable entry is held while calling 'ShouldAsyncScrollWithAnchorNotCached'. This secondary call can modify the hashtable by walking the frame tree, thereby invalidating the original reference. An attacker can exploit this by inducing a specific layout state—such as moving numerous anchor-positioned elements—leading to memory corruption. This can result in a browser tab crash or potentially arbitrary code execution. The vulnerability is fixed in Firefox version 147.0.2.
Affected products
- Mozilla Firefox < 147.0.2
Timeline
- 2026-01-27: disclosed
- 2026-01-27: patched: Fixed in Firefox 147.0.2