CVE-2026-2783

7.5

Mozilla · Firefox, Thunderbird

A JIT miscompilation flaw in the Mozilla JavaScript Engine allows for information disclosure. Attackers can exploit this via malicious web content to access sensitive data.

Executive summary

A critical information disclosure vulnerability in the Mozilla JavaScript Engine affects Firefox and Thunderbird, potentially allowing attackers to bypass security boundaries via malicious web content.

Vulnerability

This vulnerability is caused by a JIT miscompilation error within the JavaScript engine. It is an unauthenticated, remotely exploitable issue that requires user interaction, such as visiting a compromised webpage.

Business impact

The ability for an unauthenticated attacker to extract sensitive information from the memory of a browser or email client poses a significant risk to data confidentiality. Given the CVSS score of 7.5, this high severity flaw could lead to the exposure of credentials, session tokens, or other sensitive user data, potentially facilitating further unauthorized access to internal systems.

Remediation

Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 148 or higher, or to the 140.8 ESR release, to ensure the patch is applied.

Proactive Monitoring: Review browser and application logs for unusual crashes or anomalous behavior that may indicate attempts to trigger JIT compilation errors.

Compensating Controls: While no direct virtual patch exists, organizations should enforce strict content security policies and restrict the execution of untrusted JavaScript in high-risk environments.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear risk to user data confidentiality through standard web browsing activities. Security teams must prioritize the deployment of the provided updates across all enterprise endpoints to eliminate this attack vector. Given the ubiquity of these applications, failure to patch promptly could expose the organization to widespread data exfiltration risks.

More Mozilla CVEs

Sources

Originally found and disclosed by x0e, per the CVE Program record.