BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Firefox JIT bug CVE-2026-10702 exploited via malicious webpage

Critical Firefox JIT bug leads to remote code execution via malicious webpage.

  • Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.
  • The vulnerability also compromises Tor Browser, with no user interaction required.
  • Nebula Security released a public exploit and deployed it as part of a browser-to-kernel chain targeting Android 17.
  • The bug stems from a mislabelled compiler operation that treats a memory-mutation step as a read.
  • A second-stage kernel flaw (CVE-2026-43499) provides root escalation on supported Android builds.

Nebula Security disclosed that a patched Firefox JIT flaw, tracked as CVE-2026-10702, could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Mozilla rated the bug High and fixed it in the Firefox 151.0.3 update, according to the advisory.

- Advertisement -

“No settings or additional user interaction are required,” said Eten Zou, CEO of Nebula Security, adding that every Tor Browser release incorporating a vulnerable Firefox version was affected. The bug provides arbitrary code execution inside the browser’s sandboxed renderer process, though researchers have not identified the exact Tor releases.

Nebula released public exploit material and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.

In its technical analysis, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox’s JIT compiler treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.

Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula’s released exploit reclaims the freed allocation, leaks a hidden-class pointer, and corrupts a Uint8Array to gain arbitrary memory read and write.

- Advertisement -

Mozilla’s source-level fix removes the custom read-only alias handling from ObjectToIterator, preventing the optimiser from retaining a stale pointer. The second stage, IonStack’s CVE-2026-43499 (dubbed GhostLock), is a separate Linux kernel futex flaw that carries the exploit to root on the supported Android build.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

US DoJ Seizes Xinbi Scam Marketplace, Freezes $52M in Crypto

U.S. authorities seized Telegram channels and froze $52.8 million in cryptocurrency linked to Xinbi...

Trump’s $2 gas promise breaks as Labor Day hits record $4.15

US gas prices hit a record $4.15 per gallon on Labor Day 2026, the...

Consensys splits MetaMask from institutional blockchain arm

ConsenSys will separate into two independent companies by the end of 2026, splitting its...

Meta Shares Jump 6% as Wall Street Backs New AI Agent Muse

Meta Platforms shares rose over 6% on Wednesday after Wall Street analysts endorsed the...

US Bank tests stablecoin cross-border payment; cards get stablecoin support

U.S. Bancorp successfully piloted its USBDC stablecoin to settle a cross-border payment between North...

Must Read

TOP 12 Day Trading Crypto Books For Beginners

Day trading cryptocurrencies has become an increasingly popular financial activity, offering the potential for huge returns to those who understand the market's complexities and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading