Executive brief
A type confusion vulnerability exists in Mozilla Firefox and Thunderbird when manipulating JavaScript objects via Array.pop. This flaw can result in an exploitable crash and potential arbitrary code execution.
Affected products
- Mozilla Firefox ESR < 60.7.1
- Mozilla Firefox < 67.0.3
- Mozilla Thunderbird < 60.7.2
Timeline
- 2019-07-23: disclosed: NVD Published Date
- 2022-05-23: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2019-06-18: patched: Mozilla released security advisories MFSA2019-18 and MFSA2019-20
- 2019-06-18: exploited: Reported as being exploited in targeted attacks in the wild at time of disclosure