PT-2026-21729 · Mozilla · Firefox+1
Gary Kwong
·
Published
2026-02-24
·
Updated
2026-05-11
·
CVE-2026-2796
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 148
Thunderbird versions prior to 148
Description
A JIT miscompilation issue exists in the JavaScript: WebAssembly component. JIT (Just-In-Time) compilation is a method used by browsers to improve execution speed by compiling code during runtime. This flaw can lead to a sequence of failures including use-after-free, type confusion, memory leak, and arbitrary read/write, potentially resulting in remote code execution.
Recommendations
Update Firefox to version 148 or later.
Update Thunderbird to version 148 or later.
Exploit
Fix
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Firefox
Thunderbird