#VU124307 Use After Free in Mozilla products - CVE-2026-4688
Published: March 24, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to escape the sandbox and execute arbitrary code.
The vulnerability exists due to use-after-free in the Disability Access APIs component when processing accessibility events. A remote attacker can trick the victim into visiting a specially crafted website to escape the sandbox and execute arbitrary code.