Junglewise Threat Intelligence

CVE-2026-74937: Mozilla Firefox use-after-free in JavaScript GC component

CVE-2026-74937 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird contain a use-after-free memory safety vulnerability in the JavaScript garbage collector component. An attacker could exploit this to achieve arbitrary code execution with the privileges of the user running the browser, potentially leading to system compromise or data theft.

Technical details

A use-after-free vulnerability exists in the JavaScript garbage collection (GC) component of Firefox, Firefox ESR, and Thunderbird. The vulnerability occurs when memory is freed but subsequently accessed by the GC logic, allowing an attacker to corrupt memory state or execute arbitrary code. The vulnerability is reachable through normal browser JavaScript execution (network attack vector) and requires no user authentication beyond visiting a malicious webpage. An attacker can craft JavaScript code that triggers the use-after-free condition to achieve remote code execution. Mozilla has patched this issue in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 153.1
  • Mozilla Thunderbird before 154
  • Mozilla Thunderbird ESR before 153.1

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1

References

Related threats