Executive brief
Firefox's HTML parser component contains a use-after-free vulnerability that can allow an attacker to execute arbitrary code by accessing memory that has been freed. This affects millions of Firefox users and could enable remote code execution through a malicious webpage without user interaction beyond normal browsing.
Technical details
A use-after-free vulnerability exists in the DOM: HTML Parser component, where freed memory is accessed after deallocation. This memory safety issue can be triggered through crafted HTML content sent to a vulnerable browser. An attacker can exploit this through a malicious webpage delivered over the network—no authentication or special user interaction is required beyond normal browsing. Successful exploitation allows arbitrary code execution with the privileges of the browser process. Patches are available in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, and Firefox ESR 153.3.
Affected products
- Mozilla Firefox before 156
- Mozilla Firefox ESR 115 before 115.41; 140 before 140.16; 153 before 153.3
- Mozilla Thunderbird before 156; 140 before 140.16; 153 before 153.3
Timeline
- 2026-09-15: disclosed: Vulnerability disclosed in Mozilla Security Advisory MFSA2026-90
- 2026-09-15: patched: Fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3