Junglewise Threat Intelligence

CVE-2026-4698: Mozilla Firefox and Thunderbird JIT miscompilation in JavaScript Engine

CVE-2026-4698 · Severity: critical · CVSS 9.8 · Published 2026-03-24

Technologies: Mozilla Thunderbird, Mozilla Firefox ESR, Mozilla Thunderbird ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A critical vulnerability exists in the JavaScript engine used by Mozilla Firefox and Thunderbird. This flaw allows a malicious website or email to potentially execute unauthorized code on a user's computer by exploiting how the browser optimizes script performance. Successful exploitation could lead to full system compromise, data theft, or the installation of malware.

Technical details

A JIT miscompilation vulnerability exists within the JIT component of the Mozilla JavaScript Engine (SpiderMonkey). The flaw is characterized as a type confusion (CWE-843) where the engine incorrectly optimizes code, leading to incompatible resource access. An attacker can exploit this by enticing a user to visit a malicious webpage or view a specially crafted email, potentially achieving remote code execution (RCE) with the privileges of the application. The vulnerability was reported by maxpl0it via Trend Micro Zero Day Initiative and is addressed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, and corresponding Thunderbird versions.

Affected products

  • Mozilla Firefox < 149
  • Mozilla Firefox ESR < 115.34, 128.x < 140.9
  • Mozilla Thunderbird < 149
  • Mozilla Thunderbird ESR < 140.9

Timeline

  • 2026-03-24: disclosed
  • 2026-03-24: advisory
  • 2026-03-24: patched

References

Related threats