Executive brief
Mozilla Firefox is a widely used web browser. A vulnerability in its WebAssembly component could allow a malicious website to execute unauthorized code or crash the browser when a user visits a specially crafted page. This could lead to the theft of sensitive information or a complete compromise of the user's computer.
Technical details
An incorrect boundary condition vulnerability exists in the JavaScript: WebAssembly component of Mozilla Firefox. The flaw is rooted in improper validation of array or buffer boundaries during WebAssembly execution. An attacker can exploit this by enticing a user to visit a malicious website containing specially crafted WebAssembly code. Successful exploitation could lead to memory corruption, potentially allowing for arbitrary code execution within the context of the browser process or a denial-of-service (browser crash). The vulnerability is addressed in Firefox 153 and Firefox ESR 140.13.
Affected products
- Mozilla Firefox < 153
- Mozilla Firefox ESR < 140.13
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched
- 2026-07-21: advisory