CVE-2026-24869
published 2026-01-27CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.23%
14.0th percentile
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability was fixed in Firefox 147.0.2.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 147.0.2-1 (sid) | firefox 147.0.2-1 (sid) |
| mozilla | firefox | < 147.0.2 | 147.0.2 |
| mozilla | firefox | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: Use-after-free in the Layout: Scrolling and Overflow component
vendor_redhat·2026-01-27·CVSS 8.8
CVE-2026-24869 [HIGH] firefox: Use-after-free in the Layout: Scrolling and Overflow component
firefox: Use-after-free in the Layout: Scrolling and Overflow component
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Use-after-free in the Layout: Scrolling and Overflow component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affe
Debian
CVE-2026-24869: firefox - Use-after-free in the Layout: Scrolling and Overflow component. This vulnerabili...
vendor_debian·2026·CVSS 8.8
CVE-2026-24869 [HIGH] CVE-2026-24869: firefox - Use-after-free in the Layout: Scrolling and Overflow component. This vulnerabili...
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.
Scope: local
sid: resolved (fixed in 147.0.2-1)
Mozilla
Mozilla Foundation Security Advisory 2026-06: CVE-2026-24869
vendor_mozilla·CVSS 8.8
CVE-2026-24869 [HIGH] Mozilla Foundation Security Advisory 2026-06: CVE-2026-24869
Mozilla Foundation Security Advisory 2026-06
CVE: CVE-2026-24869
Product: Firefox
Impact: high
Fixed in: Firefox 147.0.2
VulDB
Mozilla Firefox up to 147.0.1 Layout use after free (Nessus ID 297406 / WID-SEC-2026-0232)
vuldb·2026-07-01·CVSS 8.8
CVE-2026-24869 [HIGH] Mozilla Firefox up to 147.0.1 Layout use after free (Nessus ID 297406 / WID-SEC-2026-0232)
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 147.0.1. This affects an unknown function of the component Layout. The manipulation leads to use after free.
This vulnerability is listed as CVE-2026-24869. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
OSV
CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow component
osv·2026-01-27·CVSS 8.8
CVE-2026-24869 [HIGH] CVE-2026-24869: Use-after-free in the Layout: Scrolling and Overflow component
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.
GHSA
GHSA-5hpc-pqrr-8j6m: Use-after-free in the Layout: Scrolling and Overflow component
ghsa_unreviewed·2026-01-27
CVE-2026-24869 [HIGH] CWE-416 GHSA-5hpc-pqrr-8j6m: Use-after-free in the Layout: Scrolling and Overflow component
Use-after-free in the Layout: Scrolling and Overflow component. This vulnerability affects Firefox < 147.0.2.
No detection rules found.
No public exploits indexed.
2026-01-27
Published