Junglewise Threat Intelligence

CVE-2026-16355: Mozilla Firefox JIT miscompilation in JavaScript Engine

CVE-2026-16355 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the JavaScript engine of Mozilla Firefox, which is the component responsible for running web applications and scripts. A flaw in how the browser optimizes code (JIT compilation) could allow a malicious website to compromise the browser's security. This could lead to unauthorized access to data or the execution of malicious code on the user's system.

Technical details

A JIT (Just-In-Time) miscompilation vulnerability was identified in the JavaScript Engine's JIT component of Mozilla Firefox. The issue arises during the optimization of JavaScript code, where incorrect machine code generation can lead to type confusion or memory safety violations. An attacker can exploit this by enticing a user to visit a specially crafted website, potentially achieving remote code execution (RCE) within the context of the browser process. The vulnerability is addressed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 115.38, < 140.13

Timeline

  • 2026-07-21: advisory: Mozilla Foundation Security Advisory published
  • 2026-07-21: patched

References

Related threats