BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Firefox JIT bug CVE-2026-10702 exploited via malicious webpage

Critical Firefox JIT bug leads to remote code execution via malicious webpage.

  • Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.
  • The vulnerability also compromises Tor Browser, with no user interaction required.
  • Nebula Security released a public exploit and deployed it as part of a browser-to-kernel chain targeting Android 17.
  • The bug stems from a mislabelled compiler operation that treats a memory-mutation step as a read.
  • A second-stage kernel flaw (CVE-2026-43499) provides root escalation on supported Android builds.

Nebula Security disclosed that a patched Firefox JIT flaw, tracked as CVE-2026-10702, could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Mozilla rated the bug High and fixed it in the Firefox 151.0.3 update, according to the advisory.

- Advertisement -

“No settings or additional user interaction are required,” said Eten Zou, CEO of Nebula Security, adding that every Tor Browser release incorporating a vulnerable Firefox version was affected. The bug provides arbitrary code execution inside the browser’s sandboxed renderer process, though researchers have not identified the exact Tor releases.

Nebula released public exploit material and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.

In its technical analysis, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox’s JIT compiler treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.

Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula’s released exploit reclaims the freed allocation, leaks a hidden-class pointer, and corrupts a Uint8Array to gain arbitrary memory read and write.

- Advertisement -

Mozilla’s source-level fix removes the custom read-only alias handling from ObjectToIterator, preventing the optimiser from retaining a stale pointer. The second stage, IonStack’s CVE-2026-43499 (dubbed GhostLock), is a separate Linux kernel futex flaw that carries the exploit to root on the supported Android build.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron stock all-time high talk grows pre Sept. 30 earnings

Micron shares trade near $980, over 20% below the June 2026 closing record of...

Pencil Finance completes $1M on-chain student loan cycle

Pencil Finance completed a $1 million student-loan cycle fully on-chain, from investor capital to...

Bitcoin Trades More Like Gold, Bolstering Digital Gold Case

Bitcoin's 90-day correlation with Gold climbed to its highest level since 2020, while its...

Orionx shuts after $7M custody loss, blames co-founders

Chilean crypto exchange Orionx is shutting down after a forensic audit discovered over $7...

MikroTik SSH exploit grants full admin control without auth

Attackers are exploiting a critical vulnerability in MikroTik RouterOS that grants full administrative control...

Must Read

What Is a Sim Swap Hack?

You've likely heard the term 'sim-swap,' but do you really know what it means? It's a type of fraud that's rapidly increasing, where scammers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading