Description
JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A miscompilation in the JavaScript engine’s JIT layer causes the browser to generate incorrect native code from JavaScript bytecode. This flaw can be leveraged by an attacker to execute arbitrary instructions in the context of the browser process, leading to a complete compromise of the user’s system. The weakness aligns with the formal weakness of code execution via miscompiled instructions.

Affected Systems

Mozilla Firefox users running versions prior to 157 are affected, as the issue was remediated in Firefox 157. The ground truth for specific obsolete sub‑versions is not listed, but any release before 157 inherits the vulnerability.

Risk and Exploitability

The exploit requires the attacker to deliver malicious or specially crafted JavaScript that the victim’s browser will execute. While no EPSS metric is currently available and the vulnerability is not in the CISA KEV catalog, the severity implied by the possibility of arbitrary code execution and the absence of a mitigation other than updating denotes a high risk to any user who loads untrusted web content.

Generated by OpenCVE AI on September 29, 2026 at 17:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 157 or later
  • Disable JavaScript in browser settings or use a stricter security mode until the update is applied
  • Implement a Content Security Policy (CSP) that restricts trusted sources for script execution as an additional protective measure

Generated by OpenCVE AI on September 29, 2026 at 17:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-62

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description JIT miscompilation in the JavaScript Engine component. This vulnerability was fixed in Firefox 157.
Title JIT miscompilation in the JavaScript Engine component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:14.014Z

Reserved: 2026-09-26T19:17:25.865Z

Link: CVE-2026-100793

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:44.340

Modified: 2026-09-29T13:17:44.340

Link: CVE-2026-100793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:30:17Z

Weaknesses