What is CVE-2026-74937?
CVE-2026-74937 is a use-after-free vulnerability in the JavaScript: GC (Garbage Collector) component of the Firefox browser. Successful exploitation could lead to remote code execution (RCE). The vulnerability has been fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1, so users should update to these versions.
Azərbaycanca: CVE-2026-74937, Firefox brauzerinin JavaScript: GC (Garbage Collector) komponentində istifadə edilmiş yaddaşa (use-after-free) müraciət zəifliyidir. Bu boşluq uğurla istismar edilərsə, uzaqdan kod icrası (RCE) ilə nəticələnə bilər. Zəiflik Firefox 154, Firefox ESR 153.1, Thunderbird 154 və Thunderbird 153.1 versiyalarında aradan qaldırılıb, ona görə də istifadəçilər qeyd olunan versiyalara yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
In which software component was CVE-2026-74937 discovered?
This vulnerability was discovered in the JavaScript: GC (Garbage Collector) component of the Firefox browser.
Which versions should be updated to in order to be protected from CVE-2026-74937?
You need to update to Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.