Junglewise Threat Intelligence

CVE-2026-74936: Mozilla Firefox use-after-free in JavaScript WebAssembly

CVE-2026-74936 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird browsers contain a use-after-free vulnerability in the WebAssembly component that could allow an attacker to execute arbitrary code or crash the browser. This is a memory safety issue in a core JavaScript engine feature used by many websites. An attacker could exploit this by hosting a malicious webpage that a user visits, leading to potential system compromise or denial of service.

Technical details

This is a use-after-free vulnerability in the JavaScript WebAssembly engine component (CWE-416). The vulnerability allows an attacker to access memory that has been freed, potentially leading to code execution or information disclosure. The attack vector is network-based and requires user interaction (visiting a malicious website). No authentication or special privileges are required; any user viewing an attacker-controlled webpage is at risk. Mozilla has patched the issue in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1. The CVSS v3.1 score of 9.8 reflects the high exploitability and severe impact potential.

Affected products

  • Mozilla Firefox Before 154
  • Mozilla Firefox ESR 140.x before 140.14, 153.x before 153.1
  • Mozilla Thunderbird Before 154
  • Mozilla Thunderbird 140.x before 140.14, 153.x before 153.1

Timeline

  • 2026-08-18: disclosed: Mozilla Security Advisory 2026-74 published
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1

References

Related threats