PT-2026-45823 · Mozilla · Firefox

·

CVE-2026-10702

·

Published

2026-06-02

·

Updated

2026-07-29

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 151.0.3
Description A JIT miscompilation issue exists in the JavaScript Engine's JIT component, where JIT refers to Just-In-Time compilation, a method of improving program execution speed by compiling code during runtime. This flaw involves type confusion errors that can be exploited by a remote attacker to execute arbitrary code within the browser's renderer process. Real-world incidents indicate this issue has been used as the first stage in a full chain browser-to-kernel exploit to achieve root access on Android 17 devices via a single visit to a malicious webpage.
Recommendations Update to version 151.0.3 or later.

Exploit

Fix

DoS

RCE

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10106
CVE-2026-10702
OPENSUSE-SU-2026:10977-1
OPENSUSE-SU-2026:11373-1

Affected Products

Firefox