CVE-2026-8390
published 2026-05-12CVE-2026-8390: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
PriorityP342high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.50%
39.8th percentile
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | < Firefox 150.0.3 | Firefox 150.0.3 |
| mozilla | firefox | < 150.0.3 | 150.0.3 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Mozilla Firefox up to 150.0.2 WebAssembly use after free (EUVD-2026-29465 / WID-SEC-2026-1503)
vuldb·2026-06-17·CVSS 7.3
CVE-2026-8390 [HIGH] Mozilla Firefox up to 150.0.2 WebAssembly use after free (EUVD-2026-29465 / WID-SEC-2026-1503)
A vulnerability classified as critical was found in Mozilla Firefox up to 150.0.2. This impacts an unknown function of the component WebAssembly. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-8390. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
GHSA
GHSA-ggqh-jgm2-3w29: Use-after-free in the JavaScript: WebAssembly component
ghsa_unreviewed·2026-05-12
CVE-2026-8390 [HIGH] CWE-416 GHSA-ggqh-jgm2-3w29: Use-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
Red Hat
firefox: Use-after-free in the JavaScript: WebAssembly component
vendor_redhat·2026-05-12·CVSS 7.3
CVE-2026-8390 [HIGH] CWE-825 firefox: Use-after-free in the JavaScript: WebAssembly component
firefox: Use-after-free in the JavaScript: WebAssembly component
A flaw was found in Firefox. The Mozilla Foundation's Security Advisory describes the following issue:
Use-after-free in the JavaScript: WebAssembly component
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.
Package: firefox (Red Hat Enterprise Linux 10) - Not affected
Package: rhel10/firefox-flatpak (Red Hat Enterprise Linux 10) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
Package: firefox (Red Hat Enterprise Linux 7) - Not affected
Package: firefox (Red Hat Enterprise Linux 8) - Not affected
Package: firefox (Red Hat Enterprise Linux 9) - Not affected
Mozilla
Mozilla Foundation Security Advisory 2026-45: CVE-2026-8390
vendor_mozilla
CVE-2026-8390 Mozilla Foundation Security Advisory 2026-45: CVE-2026-8390
Mozilla Foundation Security Advisory 2026-45
CVE: CVE-2026-8390
Product: Firefox
Impact: high
Fixed in: Firefox 150.0.3
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8390 firefox: Use-after-free in the JavaScript: WebAssembly component
bugzilla·2026-05-12·CVSS 7.3
CVE-2026-8390 [HIGH] CVE-2026-8390 firefox: Use-after-free in the JavaScript: WebAssembly component
CVE-2026-8390 firefox: Use-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
Hackernews
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
blogs_hackernews·2026-06-23
CVE-2026-47729 OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws
OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the Daybreak initiative the artificial intelligence (AI) company announced last month.
Calling GPT‑5.5‑Cyber its "strongest model yet for finding and helping patch software vulnerabilities," OpenAI said the model can "sustain deeper analysis across large codebases" to identify security issues, validate them in a controlled environment, and develop and test patches.
In tandem, the tech upstart is releasing an update to the Codex S
2026-05-12
Published