


Perceptive Security
SOC/SIEM Consultancy

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.
Published:
23 maart 2026 om 23:00:00
Alert date:
24 maart 2026 om 21:04:20
Source:
nvd.nist.gov
Web Technologies
A JIT (Just-In-Time) miscompilation vulnerability has been identified in the JavaScript Engine JIT component of Firefox browsers. This security flaw affects multiple versions of Firefox, including the standard Firefox browser versions prior to 149 and Firefox Extended Support Release (ESR) versions prior to 115.34 and 140.9. JIT compilation vulnerabilities can potentially allow attackers to execute arbitrary code or bypass security mechanisms by exploiting flaws in the JavaScript engine's optimization process. The vulnerability has been assigned CVE-2026-4698 and affects a significant number of Firefox installations across different release channels.
Technical details
Mitigation steps:
Affected products:
Firefox
Firefox ESR
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4698
https://bugzilla.mozilla.org/show_bug.cgi?id=2020906
https://www.mozilla.org/security/advisories/mfsa2026-20/
https://www.mozilla.org/security/advisories/mfsa2026-21/
https://www.mozilla.org/security/advisories/mfsa2026-22/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
