Impact
A miscompilation bug in the JavaScript: WebAssembly JIT engine can cause the browser to generate incorrect machine instructions when executing WebAssembly modules. This flaw allows an attacker to craft specially designed JavaScript or WebAssembly payloads that make the JIT produce arbitrary code leading to remote code execution on the client machine. The impact is full compromise of the affected user’s system, granting the attacker the privileges of the browser process, and potentially enabling further lateral movement or data theft.
Affected Systems
The vulnerability affects all Mozilla Firefox releases prior to Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. Users running these older builds, or any builds that have not received the corresponding patch, are exposed. All platforms where Firefox operates are impacted because the issue resides in the core JIT engine.
Risk and Exploitability
The CVSS score is not provided in the publicly listed data, but the nature of the flaw—arbitrary code execution via a web‑originated payload—suggests a high‑severity risk. EPSS data is unavailable, so the likelihood of exploitation cannot be quantified from public metrics, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the weakness by loading malicious WebAssembly or JavaScript on any page reachable by the user; the JIT miscompilation occurs during normal, trusted execution of script, so the attack requires no elevated privileges or additional setup.
OpenCVE Enrichment