CVE-2026-4711 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 25, 2026
Mozilla Firefox - Use After Free
Overview
Mozilla Firefox < 149 and Firefox ESR < 140.9 contain a use-after-free vulnerability caused by improper memory management in the Widget: Cocoa component, letting attackers potentially execute arbitrary code, exploit requires crafted input.
Severity & Score
Impact
Attackers can execute arbitrary code remotely, potentially leading to full system compromise.
Mitigation
Update to Firefox 149 and Firefox ESR 140.9 or later.
References
Social Media Activity(1 post)
š“ CVE-2026-4711 - Critical (9.8) Use-after-free in the Widget: Cocoa component. This vulnerability affects Firefox < 149, Firefox ESR < 140.9, Thunderbird < 149, and Thunderbird < 140.9. š https://www.thehackerwire.com/vulnerability/CVE-2026-4711/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-4711
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- use_after_free
- Status
- modified
- EPSS
- 1.7%
- Social Posts
- 1
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H