BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Firefox JIT bug CVE-2026-10702 exploited via malicious webpage

Critical Firefox JIT bug leads to remote code execution via malicious webpage.

  • Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.
  • The vulnerability also compromises Tor Browser, with no user interaction required.
  • Nebula Security released a public exploit and deployed it as part of a browser-to-kernel chain targeting Android 17.
  • The bug stems from a mislabelled compiler operation that treats a memory-mutation step as a read.
  • A second-stage kernel flaw (CVE-2026-43499) provides root escalation on supported Android builds.

Nebula Security disclosed that a patched Firefox JIT flaw, tracked as CVE-2026-10702, could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Mozilla rated the bug High and fixed it in the Firefox 151.0.3 update, according to the advisory.

- Advertisement -

“No settings or additional user interaction are required,” said Eten Zou, CEO of Nebula Security, adding that every Tor Browser release incorporating a vulnerable Firefox version was affected. The bug provides arbitrary code execution inside the browser’s sandboxed renderer process, though researchers have not identified the exact Tor releases.

Nebula released public exploit material and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.

In its technical analysis, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox’s JIT compiler treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.

Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula’s released exploit reclaims the freed allocation, leaks a hidden-class pointer, and corrupts a Uint8Array to gain arbitrary memory read and write.

- Advertisement -

Mozilla’s source-level fix removes the custom read-only alias handling from ObjectToIterator, preventing the optimiser from retaining a stale pointer. The second stage, IonStack’s CVE-2026-43499 (dubbed GhostLock), is a separate Linux kernel futex flaw that carries the exploit to root on the supported Android build.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Emirates launches crypto payments for flights via Crypto.com

Emirates has integrated crypto.com Pay on its website and app, allowing eligible UAE residents...

Cardano Price Surges on AI Developer Skills Launch

Cardano (ADA) surged 5.4% in 24 hours and 13.4% over the past month, outperforming...

Apple Sued Over Fake Bitcoin App That Drained $1.8 Million

Three Bitcoin holders have sued Apple in a California federal court, alleging a counterfeit...

Grayscale: HYPE circulating supply 270-310M by 2027

Grayscale Research projects Hyperliquid could generate $1 billion in annual revenue by 2027, using...

Bitcoin ETFs bleed $526M as BTC fails to hold $65K

US spot Bitcoin ETFs recorded four consecutive trading sessions of net outflows totaling approximately...

Must Read

This is How to Buy and Sell Bitcoin

Now more than ever, there are a variety of ways to enter and exit the crypto market. While this is good, the availability of...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading