Executive brief
A vulnerability exists in the Firefox web browser's WebAssembly engine, which is used to run high-performance applications in the browser. An attacker could potentially exploit this flaw to cause the browser to behave unexpectedly or crash when processing malicious web content. This issue has been resolved in Firefox version 152.
Technical details
A JIT (Just-In-Time) miscompilation vulnerability exists in the JavaScript: WebAssembly component of Mozilla Firefox. The flaw occurs when the JIT compiler incorrectly translates WebAssembly code into machine instructions, potentially leading to memory corruption or logic errors. An attacker can exploit this by enticing a user to visit a specially crafted website containing malicious WebAssembly. This vulnerability is fixed in Firefox 152.
Affected products
- Mozilla Firefox < 152
Timeline
- 2026-06-16: advisory: Mozilla Foundation Security Advisory 2026-57 published.
- 2026-06-16: patched: Fixed in Firefox 152.