CVE-2026-4691 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 24, 2026
Firefox - Use After Free
Published: March 24, 2026Updated: March 24, 2026Remote Exploitable
Overview
Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9 contain a use-after-free vulnerability caused by flaws in the CSS Parsing and Computation component, letting attackers cause memory corruption, exploit requires crafted content.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can cause memory corruption leading to potential code execution or application crash.
Mitigation
Update to Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-4691
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- use_after_free
- Status
- confirmed
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H