Executive brief
Firefox's DOM (Document Object Model) navigation component contains a use-after-free vulnerability that allows an attacker to escape the browser's security sandbox and execute arbitrary code. This could enable a malicious website to fully compromise a user's system, stealing sensitive data, installing malware, or taking control of the device.
Technical details
A use-after-free vulnerability exists in the DOM Navigation component, where memory is accessed after it has been freed, potentially allowing arbitrary code execution. The flaw requires no additional privileges or user interaction beyond visiting a malicious webpage. An attacker can craft a specially designed website to trigger the vulnerability and escape Firefox's sandbox, gaining the ability to run code at system privileges. The vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
Affected products
- Mozilla Firefox before 155
- Mozilla Firefox ESR 115 before 115.40, 140 before 140.15, 153 before 153.2
- Mozilla Thunderbird before 155, 140 before 140.15, 153 before 153.2
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Firefox 155, Firefox ESR 115.40/140.15/153.2, Thunderbird 155/140.15/153.2