CVE-2026-0884: Use-after-free in the JavaScript Engine component
Use-after-free in the JavaScript Engine component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.
Other sources
Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0884?
CVE-2026-0884 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2026-0884?
To address CVE-2026-0884, update Firefox to version 147 or Firefox ESR to version 140.7 or later.
What versions of Firefox are affected by CVE-2026-0884?
CVE-2026-0884 affects Firefox versions prior to 147 and Firefox ESR versions prior to 140.7.
What does the term 'use-after-free' mean in the context of CVE-2026-0884?
'Use-after-free' refers to a vulnerability where a program continues to use memory that has already been freed, potentially leading to arbitrary code execution.
Is there a workaround for CVE-2026-0884?
There is no known workaround for CVE-2026-0884; the recommended action is to apply the necessary updates.