Junglewise Threat Intelligence

CVE-2026-15718: Mozilla Firefox invalid pointer in JavaScript WebAssembly

CVE-2026-15718 · Severity: medium · CVSS 4.3 · Published 2026-07-14

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the Mozilla Firefox web browser. This flaw affects the component responsible for running high-performance web applications (WebAssembly). If exploited, it could lead to application instability or unauthorized access to limited information, though no active attacks have been reported in the wild.

Technical details

A vulnerability classified as a 'Release of Invalid Pointer or Reference' (CWE-763) exists within the JavaScript: WebAssembly component of Mozilla Firefox. The flaw involves an invalid pointer that can be triggered during the execution of WebAssembly code. While the CISA-ADP CVSS score is 4.3 (Medium), Mozilla has rated the impact as 'Critical'. An attacker could potentially leverage this to achieve remote code execution or a denial-of-service condition, though exploitation requires a user to visit a specially crafted webpage. Public exploit code is reportedly available, but no active exploitation has been observed. The issue is resolved in Firefox version 152.0.6.

Affected products

  • Mozilla Firefox versions prior to 152.0.6

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched

References

Related threats