Description
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3.
Published: 2026-05-12
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unspecified flaw exists in the JavaScript Engine component of Mozilla Firefox. The vulnerability could allow an attacker to influence script execution or the handling of JavaScript code, potentially affecting confidentiality, integrity, or availability of the affected system. The CVE description confirms only that a fix was applied in Firefox 150.0.3.

Affected Systems

Mozilla Firefox installations running any version older than 150.0.3 are affected. No additional product or vendor specificity is provided.

Risk and Exploitability

The CVSS score is not available, and the EPSS score is missing, indicating that the severity and exploit probability are unknown from the public data. The vulnerability is not listed in CISA's KEV catalog, reducing evidence of active exploitation. The likely attack vector is inferred to be web-based or browser-context attacks that deliver malicious JavaScript, but no explicit attack path is documented in the description. Without concrete exploitation evidence, the risk is judged to be uncertain but potentially significant for vulnerable browsers.

Generated by OpenCVE AI on May 12, 2026 at 15:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 150.0.3 or a later release from trusted Mozilla sources
  • Enable automatic updates to ensure future security fixes are applied promptly
  • If upgrading immediately is not possible, restrict or disable JavaScript execution from untrusted or external domains as a temporary mitigation

Generated by OpenCVE AI on May 12, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 12 May 2026 15:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CWE-94

Tue, 12 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 12 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3.
Title Other issue in the JavaScript Engine component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-05-12T12:36:15.548Z

Reserved: 2026-05-12T12:36:14.816Z

Link: CVE-2026-8391

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-12T14:17:12.173

Modified: 2026-05-12T14:20:56.547

Link: CVE-2026-8391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-12T15:30:18Z

Weaknesses