Invalid Pointer Vulnerability in Firefox JavaScript Engine
CVE-2026-100813

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100813?

This vulnerability pertains to an invalid pointer dereference issue within the JIT (Just-In-Time) component of the JavaScript Engine in Firefox. Attackers exploiting this flaw could potentially execute arbitrary code or cause a crash, impacting user safety and system security. Mozilla has addressed this vulnerability in Firefox version 157, and users are strongly encouraged to update to this version or later to mitigate potential risks. For further details, refer to Mozilla's advisory about this security flaw.

Affected Version(s)

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.