Executive brief
Mozilla Firefox is a widely used web browser. A vulnerability in its WebAssembly component—which handles high-performance code execution—could allow a malicious website to cause an integer overflow. This type of flaw can lead to browser crashes or potentially allow an attacker to gain unauthorized control over the user's browser session.
Technical details
An integer overflow vulnerability was identified in the JavaScript: WebAssembly component of Mozilla Firefox. The flaw occurs during the processing of WebAssembly code, which is a binary instruction format for a stack-based virtual machine. An attacker can exploit this by enticing a user to visit a specially crafted webpage, potentially leading to memory corruption or arbitrary code execution within the context of the browser process. The vulnerability is addressed in Firefox 153 and Firefox ESR 140.13.
Affected products
- Mozilla Firefox < 153
- Mozilla Firefox ESR < 140.13
Timeline
- 2026-07-21: disclosed
- 2026-07-21: patched
- 2026-07-21: advisory