Description
JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A miscompilation bug in the JavaScript: WebAssembly JIT engine can cause the browser to generate incorrect machine instructions when executing WebAssembly modules. This flaw allows an attacker to craft specially designed JavaScript or WebAssembly payloads that make the JIT produce arbitrary code leading to remote code execution on the client machine. The impact is full compromise of the affected user’s system, granting the attacker the privileges of the browser process, and potentially enabling further lateral movement or data theft.

Affected Systems

The vulnerability affects all Mozilla Firefox releases prior to Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. Users running these older builds, or any builds that have not received the corresponding patch, are exposed. All platforms where Firefox operates are impacted because the issue resides in the core JIT engine.

Risk and Exploitability

The CVSS score is not provided in the publicly listed data, but the nature of the flaw—arbitrary code execution via a web‑originated payload—suggests a high‑severity risk. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified from public metrics, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness by loading malicious WebAssembly or JavaScript on any page reachable by the user; the JIT miscompilation occurs during normal, trusted execution of script, so the attack requires no elevated privileges or additional setup.

Generated by OpenCVE AI on September 29, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version ESR 153.4 or newer, or to Firefox 157 or newer, which incorporate the JIT fix
  • Ensure that all Firefox installations are kept up to date through the browser’s update mechanism or an enterprise patch management system
  • If immediate upgrade is not possible, monitor for and apply any interim security advisories from Mozilla and consider disabling or restricting WebAssembly execution in browsers that allow it

Generated by OpenCVE AI on September 29, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
Title JIT miscompilation in the JavaScript: WebAssembly component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:13.478Z

Reserved: 2026-09-26T19:17:23.406Z

Link: CVE-2026-100792

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:44.237

Modified: 2026-09-29T13:17:44.237

Link: CVE-2026-100792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:45:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer