Junglewise Threat Intelligence

CVE-2026-12299: Mozilla Firefox JIT miscompilation in DOM Core and HTML

CVE-2026-12299 · Severity: info · Published 2026-06-16

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the Firefox web browser's engine that handles core web page content and HTML. This flaw could allow a malicious website to execute unauthorized code or compromise the browser's security by exploiting errors in how the browser optimizes JavaScript. Successful exploitation could lead to the theft of sensitive user data or unauthorized access to the user's system.

Technical details

A JIT (Just-In-Time) miscompilation vulnerability exists within the DOM: Core & HTML component of Mozilla Firefox. The issue stems from incorrect optimization of JavaScript code by the JIT compiler when interacting with specific DOM elements or HTML structures. An attacker could exploit this by enticing a user to visit a specially crafted website, leading to memory corruption or type confusion. This could potentially be leveraged for arbitrary code execution within the context of the browser process. The vulnerability is addressed in Firefox 152, Firefox ESR 140.12, and Firefox ESR 115.37.

Affected products

  • Mozilla Firefox < 152
  • Mozilla Firefox ESR < 140.12, < 115.37

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched
  • 2026-06-16: advisory

References

Related threats