Mozilla Firefox and Firefox ESR JIT Miscompilation Vulnerability

Vulnerability

A Just-In-Time (JIT) miscompilation vulnerability has been identified in the JavaScript engine of Mozilla Firefox. This issue affects Firefox versions prior to 146 and Firefox ESR versions prior to 140.6. The vulnerability arises from incorrect optimizations in the JIT compilation process, which could potentially be exploited to cause unexpected behavior in the JavaScript engine.

Impact

Exploitation of this vulnerability could lead to JIT spraying, a technique that manipulates the JIT compiler's optimization process. This could potentially be used to execute arbitrary code or cause a crash.

Remediation

Users can upgrade to Firefox 146 or Firefox ESR 140.6 to address this vulnerability.

Added: Dec 9, 2025, 8:35 PM
Updated: Dec 9, 2025, 8:35 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.