CVE-2026-16410

9.8

Mozilla · Firefox, Thunderbird

A JIT miscompilation vulnerability within the JavaScript engine allows unauthenticated attackers to potentially achieve remote code execution.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a critical JIT miscompilation flaw that enables unauthenticated remote code execution.

Vulnerability

The vulnerability resides in the Just-In-Time (JIT) compilation component of the JavaScript engine. It allows an unauthenticated remote attacker to trigger memory corruption and execute arbitrary code by supplying a specially crafted webpage or malicious content.

Business impact

The flaw carries a CVSS score of 9.8, indicating a critical severity level due to its potential for full system compromise. Successful exploitation could lead to total loss of confidentiality, integrity, and availability, potentially resulting in data exfiltration, malware deployment, or complete takeover of the host system.

Remediation

Immediate Action: Update both Mozilla Firefox and Thunderbird to version 153 or later immediately.

Proactive Monitoring: Review enterprise browser logs for unusual activity patterns or crashes associated with the JavaScript engine.

Compensating Controls: Deploy endpoint protection solutions capable of detecting memory corruption attempts and ensure that browser security features are enforced via group policy.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical CVSS score and the potential for unauthenticated remote code execution, this vulnerability poses a severe risk to organizational infrastructure. Security teams should prioritize the deployment of the 153 update across all managed instances of Firefox and Thunderbird immediately to mitigate the risk of exploitation.

More Mozilla CVEs

Sources

Originally found and disclosed by Amy Burnett of OpenAI, per the CVE Program record.