UAF in Firefox DOM Window/Location before v148
CVE-2026-2787 Published on February 24, 2026

Use-after-free in the DOM: Window and Location component
Use-after-free in the DOM: Window and Location component. This vulnerability affects Firefox < 148, Firefox ESR < 115.33, and Firefox ESR < 140.8.

NVD


Products Associated with CVE-2026-2787

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2026-2787 are published in these products:

 
 

Affected Versions

Mozilla Firefox: Mozilla Firefox ESR: Mozilla Firefox ESR: Mozilla Thunderbird: Mozilla Thunderbird: