Impact
JIT miscompilation in the JavaScript Engine’s JIT component allows code that has been compiled for execution to behave incorrectly, which can lead to arbitrary code execution and compromise of confidentiality, integrity, or availability. The weakness is identified as CWE‑843, incorrect type handling.
Affected Systems
Mozilla Firefox versions prior to 153 and Mozilla Thunderbird versions prior to 153 are vulnerable. The issue affects all platforms where these browsers are installed.
Risk and Exploitability
The CVSS score of 9.8 marks this as high severity. Though the EPSS score is under 1 % and it is not listed in CISA KEV, the vulnerability remains exploitable through malicious JavaScript that triggers the miscompilation. Attackers can potentially deliver payloads via web content or local scripts that are JIT‑compiled.
OpenCVE Enrichment