When Responsive Design Mode was enabled, it used references to objects that were previously freed. We presume that with enough effort this could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HMozilla Firefox
APPMozilla< 88.0Mozilla Firefox Esr
APPMozilla< 78.10Mozilla Thunderbird
APPMozilla< 78.10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References
Related vulnerabilities
CVE-2024-9680CRITICAL9.8⚠ KEVPL ✓same product
Use-after-free w Animation timelines Firefox/Thunderbird — RCE
CVE-2022-26486CRITICAL9.6⚠ KEVPL ✓same product
Use-after-free w WebGPU IPC framework Mozilla — sandbox escape
CVE-2019-11708CRITICAL10.0⚠ KEVPL ✓same product
Mozilla Firefox/Thunderbird: przełamanie sandbox przez IPC Prompt:Open
CVE-2010-3765CRITICAL9.8⚠ KEVPL ✓same product
RCE w Mozilla Firefox przez błąd nsCSSFrameConstructor::ContentAppended
CVE-2026-84119CRITICAL9.6same product
Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox...