#VU124301 Heap-based Buffer Overflow in Mozilla products - CVE-2026-4698

 

#VU124301 Heap-based Buffer Overflow in Mozilla products - CVE-2026-4698

Published: March 24, 2026


Vulnerability identifier: #VU124301
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2026-4698
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Mozilla Firefox
Firefox ESR
Firefox for Android
Software vendor:
Mozilla

Description

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing JavaScript code. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code.

Exploitation could lead to memory corruption and arbitrary code execution in the context of the browser.


Remediation

Install security update from vendor's website.

External links