CVE-2026-8953
published 2026-05-19CVE-2026-8953: Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR…
PriorityP349critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
EPSS
0.53%
41.4th percentile
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 151 | Firefox 151 |
| mozilla | firefox | < 115.36.0 | 115.36.0 |
| mozilla | firefox | < 151.0.0 | 151.0.0 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 140.0 < 140.11.0 | 140.11.0 |
| mozilla | firefox_esr | < Firefox ESR 115.36 | Firefox ESR 115.36 |
| mozilla | firefox_esr | < Firefox ESR 140.11 | Firefox ESR 140.11 |
| mozilla | thunderbird | < Thunderbird 140.11 | Thunderbird 140.11 |
| mozilla | thunderbird | < Thunderbird 151 | Thunderbird 151 |
| mozilla | thunderbird | < 140.11 | 140.11 |
| rhel10 | firefox-flatpak | — | — |
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
vendor_redhat9.6CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: Sandbox escape due to use-after-free in the Disability Access APIs component
vendor_redhat·2026-05-19·CVSS 9.6
CVE-2026-8953 [CRITICAL] CWE-825 firefox: Sandbox escape due to use-after-free in the Disability Access APIs component
firefox: Sandbox escape due to use-after-free in the Disability Access APIs component
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Sandbox escape due to use-after-free in the Disability Access APIs component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Affected
Package: firefox (Red Hat Enterprise Linux 6) - Out of support scope
Package: firefox (Red Hat Enterprise Linux 7) - Affected
Package: firefox (Red Hat Enterprise Linux 8) - Affected
Package: firefox (Red Hat Enterprise Linux 9) - Affected
Mozilla
Mozilla Foundation Security Advisory 2026-51: CVE-2026-8953
vendor_mozilla·CVSS 9.6
CVE-2026-8953 [CRITICAL] Mozilla Foundation Security Advisory 2026-51: CVE-2026-8953
Mozilla Foundation Security Advisory 2026-51
CVE: CVE-2026-8953
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 140.11
Mozilla
Mozilla Foundation Security Advisory 2026-50: CVE-2026-8953
vendor_mozilla·CVSS 9.6
CVE-2026-8953 [CRITICAL] Mozilla Foundation Security Advisory 2026-50: CVE-2026-8953
Mozilla Foundation Security Advisory 2026-50
CVE: CVE-2026-8953
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 151
Mozilla
Mozilla Foundation Security Advisory 2026-46: CVE-2026-8953
vendor_mozilla·CVSS 9.6
CVE-2026-8953 [CRITICAL] Mozilla Foundation Security Advisory 2026-46: CVE-2026-8953
Mozilla Foundation Security Advisory 2026-46
CVE: CVE-2026-8953
Product: Firefox
Impact: high
Fixed in: Firefox 151
Mozilla
Mozilla Foundation Security Advisory 2026-47: CVE-2026-8953
vendor_mozilla·CVSS 9.6
CVE-2026-8953 [CRITICAL] Mozilla Foundation Security Advisory 2026-47: CVE-2026-8953
Mozilla Foundation Security Advisory 2026-47
CVE: CVE-2026-8953
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 115.36
Mozilla
Mozilla Foundation Security Advisory 2026-48: CVE-2026-8953
vendor_mozilla·CVSS 9.6
CVE-2026-8953 [CRITICAL] Mozilla Foundation Security Advisory 2026-48: CVE-2026-8953
Mozilla Foundation Security Advisory 2026-48
CVE: CVE-2026-8953
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 140.11
GHSA
GHSA-c3qv-mh67-fpxw: Sandbox escape due to use-after-free in the Disability Access APIs component
ghsa_unreviewed·2026-05-19
CVE-2026-8953 [CRITICAL] CWE-416 GHSA-c3qv-mh67-fpxw: Sandbox escape due to use-after-free in the Disability Access APIs component
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.
VulDB
Mozilla Firefox up to 150 Disability Access API use after free
vuldb·2026-05-19·CVSS 9.6
CVE-2026-8953 [CRITICAL] Mozilla Firefox up to 150 Disability Access API use after free
A vulnerability marked as critical has been reported in Mozilla Firefox up to 150. This affects an unknown function of the component Disability Access API. This manipulation causes use after free.
The identification of this vulnerability is CVE-2026-8953. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
No detection rules found.
No public exploits indexed.
https://bugzilla.mozilla.org/show_bug.cgi?id=2029511https://www.mozilla.org/security/advisories/mfsa2026-46/https://www.mozilla.org/security/advisories/mfsa2026-47/https://www.mozilla.org/security/advisories/mfsa2026-48/https://www.mozilla.org/security/advisories/mfsa2026-50/https://www.mozilla.org/security/advisories/mfsa2026-51/
2026-05-19
Published