CVE-2026-8389 Details
Description
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
A vulnerability has been identified in Mozilla Firefox, specifically in the Just-In-Time (JIT) compilation component of the JavaScript engine. This vulnerability arises from a miscompilation issue, which could potentially be exploited under certain conditions.
Users can upgrade to Firefox version 150.0.3 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-8389 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2476466 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8389.json | redhat-SADP | |
| https://github.com/crixpwn/CVE-2026-8389 | CISA-ADP | |
| https://bugzilla.mozilla.org/show_bug.cgi?id=2036983 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2026-45/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | CISA-ADP |
| CWE-686 | Function Call With Incorrect Argument Type | CISA-ADP |
| CWE-733 | Compiler Optimization Removal or Modification of Security-critical Code | redhat-SADP |
| CWE-843 | Access of Resource Using Incompatible Type ('Type Confusion') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 150.0.3 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | New CVE Received | [email protected] |