PT-2026-45823 · Mozilla · Firefox
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox versions prior to 151.0.3
Description
A JIT miscompilation issue exists in the JavaScript Engine's JIT component, where JIT refers to Just-In-Time compilation, a method of improving program execution speed by compiling code during runtime. This flaw involves type confusion errors that can be exploited by a remote attacker to execute arbitrary code within the browser's renderer process. Real-world incidents indicate this issue has been used as the first stage in a full chain browser-to-kernel exploit to achieve root access on Android 17 devices via a single visit to a malicious webpage.
Recommendations
Update to version 151.0.3 or later.
Exploit
Fix
DoS
RCE
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Firefox