Executive brief
Firefox's JavaScript engine contains a code generation flaw in the JIT (Just-In-Time) compiler that can cause incorrect behavior during script execution. An attacker can exploit this to cause unexpected program behavior or potentially bypass security protections, impacting the confidentiality and integrity of user browsing.
Technical details
This vulnerability is a JIT miscompilation issue in the JavaScript Engine's JIT component. The flaw causes incorrect machine code generation during the compilation of JavaScript, which can lead to unexpected runtime behavior. The attack vector is network-based (malicious JavaScript delivered via web pages), and no special user interaction beyond normal web browsing is required. An attacker can craft malicious JavaScript to trigger the miscompilation and achieve information disclosure or code execution. Mozilla has patched this in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.
Affected products
- Mozilla Firefox before 154
- Mozilla Firefox ESR before 140.14 and before 153.1
- Mozilla Thunderbird before 154, before 140.14, and before 153.1
Timeline
- 2026-08-18: disclosed
- 2026-08-18: patched: Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, Thunderbird 153.1