Description
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.
Published: 2026-07-14
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves an invalid pointer that is used during the execution of a WebAssembly module by Firefox's JavaScript engine. Such a mis‑specified pointer can corrupt memory or trigger a crash. Public exploit code demonstrates that a malicious WebAssembly payload could trigger the vector, and if executed could corrupt memory, potentially enabling arbitrary code execution if an attacker can influence the WebAssembly that is executed.

Affected Systems

Both Mozilla Firefox and Thunderbird are affected; the advisory indicates that versions earlier than Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13 are vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1 % implies a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, and no wild attacks have been reported. Public exploit code exists, but the modest CVSS and very low EPSS suggest that the practical risk remains low to moderate at this time.

Generated by OpenCVE AI on August 3, 2026 at 03:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox ESR to 140.13 or newer, as it receives security updates.
  • Upgrade Thunderbird to 140.13 or newer.
  • Upgrade Mozilla Firefox to 152.0.6 or newer.
  • If an update cannot be applied immediately, disable WebAssembly execution by setting the about:config preference "javascript.options.wasm" to false or use an extension to block WebAssembly.
  • Continuously monitor Mozilla’s security advisories and apply any subsequent patches or work‑arounds as they become available.

Generated by OpenCVE AI on August 3, 2026 at 03:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6 and Firefox ESR 140.13. We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.
References

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6 and Firefox ESR 140.13.
References

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 14 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.
Title Invalid pointer in the JavaScript: WebAssembly component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:21.078Z

Reserved: 2026-07-14T12:15:45.500Z

Link: CVE-2026-15718

cve-icon Vulnrichment

Updated: 2026-07-14T13:35:01.033Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-14T12:15:46Z

Links: CVE-2026-15718 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:30:13Z

Weaknesses
  • CWE-763

    Release of Invalid Pointer or Reference