Executive brief
Mozilla Firefox is a widely used web browser. A vulnerability in its JavaScript engine could allow a malicious website to cause memory errors or potentially execute unauthorized actions. This could lead to the exposure of user data or compromise the stability of the browser. Users should update to the latest versions to protect their systems.
Technical details
A vulnerability exists in the Just-In-Time (JIT) compiler component of Mozilla's JavaScript engine due to incorrect boundary conditions (CWE-119). An attacker can exploit this by hosting a malicious website that, when visited, triggers a memory buffer error during JavaScript execution. While the reported CVSS score is 6.5 (Medium), Mozilla classifies the impact as High. Successful exploitation could lead to memory corruption, which may be leveraged for further attacks such as information disclosure or unauthorized code execution. The issue is resolved in Firefox 150.0.3, Firefox ESR 115.36, and Firefox ESR 140.11.
Affected products
- Mozilla Firefox < 150.0.3
- Mozilla Firefox ESR < 115.36, < 140.11
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Initial advisory for Firefox 150.0.3 (MFSA2026-45)
- 2026-05-19: patched: Patches released for ESR branches (MFSA2026-47, MFSA2026-48)