JIT Miscompilation in JavaScript Engine Affects Firefox by Mozilla
CVE-2026-16392

9.1CRITICAL

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
21 July 2026

What is CVE-2026-16392?

A miscompilation issue within the Just-In-Time (JIT) compilation component of the JavaScript Engine was identified in Firefox. This vulnerability could potentially lead to unexpected behavior or execution of unintended code segments, thereby affecting the overall security integrity of the browser. Mozilla has addressed this vulnerability in the release of Firefox version 153, enhancing the safety and stability of JavaScript execution within the browser.

Affected Version(s)

Firefox 153

Thunderbird 153

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gary Kwong
.