CVE-2026-10702
published 2026-06-02CVE-2026-10702: JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCNINAL
EPSS
0.72%
50.4th percentile
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 151.0.3 | Firefox 151.0.3 |
| mozilla | firefox | < 151.0.3 | 151.0.3 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
firefox: JIT miscompilation in the JavaScript Engine: JIT component
vendor_redhat·2026-06-02·CVSS 4.3
CVE-2026-10702 [MEDIUM] CWE-733 firefox: JIT miscompilation in the JavaScript Engine: JIT component
firefox: JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
JIT miscompilation in the JavaScript Engine: JIT component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Pac
Mozilla
Mozilla Foundation Security Advisory 2026-54: CVE-2026-10702
vendor_mozilla
CVE-2026-10702 Mozilla Foundation Security Advisory 2026-54: CVE-2026-10702
Mozilla Foundation Security Advisory 2026-54
CVE: CVE-2026-10702
Product: Firefox
Impact: high
Fixed in: Firefox 151.0.3
VulDB
Mozilla Firefox up to 151.0.2 JIT Remote Code Execution
vuldb·2026-06-03
CVE-2026-10702 [CRITICAL] Mozilla Firefox up to 151.0.2 JIT Remote Code Execution
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 151.0.2. This issue affects some unknown processing of the component JIT. The manipulation leads to Remote Code Execution.
This vulnerability is referenced as CVE-2026-10702. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.
GHSA
JIT miscompilation in the JavaScript Engine: JIT component.
ghsa_unreviewed·2026-06-02
CVE-2026-10702 [MEDIUM] CWE-843 JIT miscompilation in the JavaScript Engine: JIT component.
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-10702 firefox: JIT miscompilation in the JavaScript Engine: JIT component
bugzilla·2026-06-02·CVSS 4.3
CVE-2026-10702 [MEDIUM] CVE-2026-10702 firefox: JIT miscompilation in the JavaScript Engine: JIT component
CVE-2026-10702 firefox: JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.
Hackernews
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
blogs_hackernews·2026-08-03
CVE-2026-42897 ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.
Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets.
The full weekly recap report follows.
## ⚡ Threat of the Week
Anthropic Disclosed its Models Targeted 3 O
Hackernews
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
blogs_hackernews·2026-07-29·CVSS 4.3
CVE-2026-10702 [MEDIUM] Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.
Tracked as CVE-2026-10702 , the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update .
"No settings or additional user interaction are required," Eten Zou, CEO of Nebula Security, told The Hacker News. "Visiting a malicious webpage is enough to trigger it," Zou said every Tor Browser release that incorporated a v
Hackernews
15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
blogs_hackernews·2026-07-08·CVSS 7.8
CVE-2026-43499 [HIGH] 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## 15-Year-Old GhostLock Flaw Enables Root and Container Escape on Most Linux Distros
Researchers at Nebula Security have disclosed GhostLock ( CVE-2026-43499 ), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched.
The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. The flaw needs no special permission, no unusual settings, and no network access; ordinary threading calls from any local program are enough.
Nebula turned it into a working root exploit that is 97% reliable in its testing and also escapes containe
2026-06-02
Published