Executive brief
Mozilla Firefox is a widely used web browser. A vulnerability in its JavaScript engine could allow a malicious website to execute unauthorized code on a user's computer. This could lead to the theft of sensitive data, installation of malware, or complete compromise of the user's browsing session. Users should update to version 151.0.3 or later to resolve this issue.
Technical details
A JIT (Just-In-Time) miscompilation vulnerability exists in the JavaScript Engine's JIT component of Mozilla Firefox. The flaw occurs when the compiler incorrectly optimizes JavaScript code, leading to type confusion or memory corruption during execution. An attacker can exploit this by enticing a user to visit a specially crafted webpage, potentially achieving arbitrary code execution within the context of the browser process. This vulnerability was addressed in Firefox version 151.0.3 by improving the JIT compiler's validation logic.
Affected products
- Mozilla Firefox Before 151.0.3
Timeline
- 2026-06-02: advisory: Mozilla Foundation Security Advisory 2026-54 published.
- 2026-06-02: patched: Fixed in Firefox 151.0.3.