Impact
A miscompilation in the JavaScript engine’s JIT layer causes the browser to generate incorrect native code from JavaScript bytecode. This flaw can be leveraged by an attacker to execute arbitrary instructions in the context of the browser process, leading to a complete compromise of the user’s system. The weakness aligns with the formal weakness of code execution via miscompiled instructions.
Affected Systems
Mozilla Firefox users running versions prior to 157 are affected, as the issue was remediated in Firefox 157. The ground truth for specific obsolete sub‑versions is not listed, but any release before 157 inherits the vulnerability.
Risk and Exploitability
The exploit requires the attacker to deliver malicious or specially crafted JavaScript that the victim’s browser will execute. While no EPSS metric is currently available and the vulnerability is not in the CISA KEV catalog, the severity implied by the possibility of arbitrary code execution and the absence of a mitigation other than updating denotes a high risk to any user who loads untrusted web content.
OpenCVE Enrichment