Invalid Pointer Vulnerability in Firefox by Mozilla
CVE-2026-2785

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
24 February 2026

What is CVE-2026-2785?

A critical vulnerability exists in the JavaScript Engine component of Firefox, where an invalid pointer dereference can occur. This flaw affects users of Firefox versions below 148 and Firefox ESR versions lower than 140.8, potentially leading to remote code execution or application crashes. It is essential for users and organizations to update their Firefox installations to mitigate security risks and safeguard their systems against potential exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Firefox < 148

Firefox ESR < 140.8

Thunderbird < 148

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Information to follow
.