Description
Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Memory Corruption (potential RCE)
Action: Immediate Patch
AI Analysis

Impact

A flaw in the JavaScript WebAssembly component allows an invalid pointer reference, which can corrupt memory and potentially enable arbitrary code execution from a web page. This vulnerability is identified by the erroneous pointer handling in the component’s implementation. The issue was addressed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17, meaning earlier builds remain susceptible.

Affected Systems

Any user running a version of Mozilla Firefox older than ESR 153.4, Firefox 157, or ESR 140.17 may be exposed. Those build versions lack the fix for the pointer misuse in WebAssembly and are therefore vulnerable.

Risk and Exploitability

The CVSS score is not provided and the EPSS score is unavailable, but the vulnerability has not yet been observed in the CISA KEV catalog. Because the flaw can lead to memory corruption, an attacker could potentially leverage it to bypass sandboxing and execute code within the browser context. While exploitation may require specific conditions and controlled input, the severity of a successful attack would be high, justifying proactive remediation.

Generated by OpenCVE AI on September 29, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 157 or later, or to the corresponding ESR update 153.4 or 140.17.
  • Disable WebAssembly for sites that are not trusted by setting the preference javascript.options.wasm to 0 as a temporary workaround.
  • Enable site isolation and the built‑in sandbox features to limit the impact of any remaining memory corruption flaws.

Generated by OpenCVE AI on September 29, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Invalid pointer in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Title Invalid pointer in the JavaScript: WebAssembly component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:11.268Z

Reserved: 2026-09-26T19:17:13.330Z

Link: CVE-2026-100788

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:43.817

Modified: 2026-09-29T13:17:43.817

Link: CVE-2026-100788

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:45:17Z

Weaknesses