Junglewise Threat Intelligence

CVE-2026-74944: Mozilla Firefox use-after-free in DOM Core & HTML

CVE-2026-74944 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Firefox and Thunderbird handle web page rendering and email through a DOM (Document Object Model) system. A use-after-free vulnerability in this component allows an attacker to crash the browser or execute arbitrary code by tricking a user into visiting a malicious website. This could lead to data theft, malware installation, or account compromise.

Technical details

This is a use-after-free vulnerability in Firefox and Thunderbird's DOM (Document Object Model) Core & HTML processing component. The vulnerability allows an attacker to access or manipulate memory that has already been freed, potentially leading to information disclosure or arbitrary code execution. The attack requires user interaction (visiting a malicious website or opening a malicious email) but no authentication. An attacker can exploit this by crafting a malicious HTML page that triggers the use-after-free condition, achieving remote code execution with the browser process privileges. Mozilla released patches in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

Affected products

  • Mozilla Firefox before 154
  • Mozilla Firefox ESR before 140.14, before 153.1
  • Mozilla Thunderbird before 154, before 140.14, before 153.1

Timeline

  • 2026-08-18: disclosed: Publicly disclosed in Mozilla Security Advisory MFSA2026-74
  • 2026-08-18: patched: Fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1

References

Related threats