Junglewise Threat Intelligence

CVE-2026-16363: Mozilla Firefox JIT miscompilation in WebAssembly

CVE-2026-16363 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the WebAssembly component of the Firefox web browser, which is used to run high-performance applications within the browser. A flaw in how the browser optimizes code during execution could allow a malicious website to compromise the browser's security. This could lead to unauthorized access to user data or the execution of malicious code on the user's system.

Technical details

A JIT miscompilation vulnerability was identified in the JavaScript: WebAssembly component of Mozilla Firefox. The flaw occurs during the Just-In-Time compilation process, where the engine incorrectly optimizes WebAssembly code, potentially leading to type confusion or memory safety violations. An attacker could exploit this by enticing a user to visit a specially crafted website containing malicious WebAssembly, potentially achieving arbitrary code execution within the context of the browser process. The vulnerability is addressed in Firefox 153 and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox Fixed in 153
  • Mozilla Firefox ESR Fixed in 140.13

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats