Description
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird 140.9.
Product status
149 (rpm)
149 (rpm)
Credits
Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger using Claude from Anthropic
References
bugzilla.mozilla.org/show_bug.cgi?id=2013560
www.mozilla.org/security/advisories/mfsa2026-20/
www.mozilla.org/security/advisories/mfsa2026-22/
www.mozilla.org/security/advisories/mfsa2026-23/
www.mozilla.org/security/advisories/mfsa2026-24/