Executive brief
A memory management vulnerability exists in the Firefox web browser's DOM component, which handles how the browser interacts with web page content. If a user visits a specially crafted malicious website, an attacker could exploit this flaw to crash the browser or potentially execute unauthorized code on the user's computer. This could lead to the theft of sensitive information or a full compromise of the user's browsing session.
Technical details
A use-after-free vulnerability was identified in the DOM: Bindings (WebIDL) component of Mozilla Firefox. The flaw occurs when the browser continues to use a memory pointer after it has been freed, typically during the processing of WebIDL bindings which bridge JavaScript and C++ DOM implementations. An attacker can exploit this by enticing a user to visit a malicious webpage, leading to memory corruption. This can result in a browser crash (denial of service) or potentially arbitrary code execution within the context of the browser process. The vulnerability is addressed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.
Affected products
- Mozilla Firefox < 151
- Mozilla Firefox ESR < 115.36, < 140.11
Timeline
- 2026-05-19: disclosed
- 2026-05-19: patched
- 2026-05-19: advisory