BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Firefox JIT bug CVE-2026-10702 exploited via malicious webpage

Critical Firefox JIT bug leads to remote code execution via malicious webpage.

  • Critical Firefox JIT flaw (CVE-2026-10702) enables remote code execution via a malicious webpage, patched in Firefox 151.0.3.
  • The vulnerability also compromises Tor Browser, with no user interaction required.
  • Nebula Security released a public exploit and deployed it as part of a browser-to-kernel chain targeting Android 17.
  • The bug stems from a mislabelled compiler operation that treats a memory-mutation step as a read.
  • A second-stage kernel flaw (CVE-2026-43499) provides root escalation on supported Android builds.

Nebula Security disclosed that a patched Firefox JIT flaw, tracked as CVE-2026-10702, could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Mozilla rated the bug High and fixed it in the Firefox 151.0.3 update, according to the advisory.

- Advertisement -

“No settings or additional user interaction are required,” said Eten Zou, CEO of Nebula Security, adding that every Tor Browser release incorporating a vulnerable Firefox version was affected. The bug provides arbitrary code execution inside the browser’s sandboxed renderer process, though researchers have not identified the exact Tor releases.

Nebula released public exploit material and used the flaw as the first stage of IonStack, a browser-to-kernel chain built for an ARM64 device running Android 17. The released end-to-end code targets one supported Google build, although Zou said the browser flaw itself is not ARM-specific.

In its technical analysis, Nebula traces the issue to MObjectToIterator when it runs with skipRegistration set to true. Firefox’s JIT compiler treated the operation as a read even though resolving a lazy property can allocate a replacement dynamic-slots buffer and free the old one.

Global value numbering then treated a later slots-buffer load as redundant and reused the earlier pointer after it had become stale. Nebula’s released exploit reclaims the freed allocation, leaks a hidden-class pointer, and corrupts a Uint8Array to gain arbitrary memory read and write.

- Advertisement -

Mozilla’s source-level fix removes the custom read-only alias handling from ObjectToIterator, preventing the optimiser from retaining a stale pointer. The second stage, IonStack’s CVE-2026-43499 (dubbed GhostLock), is a separate Linux kernel futex flaw that carries the exploit to root on the supported Android build.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Rollbit co-founder doxxed accused of theft and rigged games

An online researcher has attempted to doxx the pseudonymous co-founder of crypto casino Rollbit,...

Crypto-backed PAC candidates win 4 of 5 primaries in key races

Four of five candidates backed by the crypto-aligned PAC Fairshake won primaries or advanced...

BRICS 2026: Modi pushes CBDC payment link at summit

The BRICS 2026 summit in New Delhi will spotlight a CBDC payment bridge to...

Base Accelerator Offers $100K to 10 AI Agent Startups

The Base accelerator plans to select 10 startups for its eight-week Batches 004 accelerator.Each...

Bitcoin Whales Accumulate Despite ETF Outflows

Bitcoin wallets holding at least 10,000 BTC climbed to 89, a six-month high, as...

Must Read

5 Best Crypto Jobs Sites To Land Your Next Six Figure Job

The cryptocurrency and blockchain job market has exploded. With new blockchain start-ups and projects being founded at a blistering pace, the demand for workers...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading