Executive brief
A vulnerability was identified in the JavaScript engine of the Firefox web browser. This component is responsible for running scripts on websites you visit. If exploited, this issue could potentially allow for unauthorized access to information or other unexpected behavior while browsing. Users should update to the latest version of Firefox to protect their data and systems.
Technical details
This vulnerability is described as an 'other issue' within the JavaScript Engine component of Mozilla Firefox. While specific root cause details are restricted in the associated Bugzilla report, CISA-ADP has associated it with CWE-20 (Improper Input Validation), CWE-79 (Cross-site Scripting), and CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer). The attack vector is network-based and requires no special privileges or user interaction. An attacker could potentially leverage this to achieve information disclosure or memory corruption. The issue is resolved in Firefox 150.0.3, Firefox ESR 115.36, and Firefox ESR 140.11.
Affected products
- Mozilla Firefox < 150.0.3
- Mozilla Firefox ESR < 115.36, < 140.11
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched