What the vulnerability does

01Description

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.

Key dates

02Disclosure timeline

March 24, 2026 CVE published
May 12, 2026 Record updated