CVE-2026-0885: Use-after-free in the JavaScript: GC component
Use-after-free in the JavaScript: GC component. This vulnerability affects Firefox < 147 and Firefox ESR < 140.7.
Other sources
Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-0885?
CVE-2026-0885 is considered a high severity vulnerability due to its potential for exploitation through use-after-free conditions.
How do I fix CVE-2026-0885?
To fix CVE-2026-0885, users should update to Firefox version 147 or Firefox ESR version 140.7 or later.
What versions of Firefox are affected by CVE-2026-0885?
CVE-2026-0885 affects Firefox versions prior to 147 and Firefox ESR versions prior to 140.7.
What is a use-after-free vulnerability in the context of CVE-2026-0885?
A use-after-free vulnerability, like CVE-2026-0885, occurs when a program continues to use a memory reference after it has been freed, potentially leading to arbitrary code execution.
Is CVE-2026-0885 exploitable remotely?
Yes, CVE-2026-0885 can be exploited remotely, allowing attackers to execute arbitrary code on the affected system.