Use-after-free in Mozilla products - CVE-2026-100818
Published: September 29, 2026
Vulnerability identifier: #VU152842
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100818
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to use-after-free in the Widget: Gtk component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.
Affected software
Firefox ESR
Mozilla Firefox
Firefox for Android
Mozilla Firefox
Firefox for Android
How to mitigate CVE-2026-100818
Install security update from vendor's website.
Firefox ESR - addressed in versions 140.17.0, 153.4.0
Firefox for Android - update to 157.0
Mozilla Firefox - update to 157.0
Firefox for Android - update to 157.0
Mozilla Firefox - update to 157.0