
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4702 is a JIT miscompilation vulnerability in the JavaScript Engine component of Mozilla Firefox and Thunderbird. The flaw allows type confusion attacks through incorrect code generation by the Just-In-Time compiler, potentially enabling arbitrary code execution or denial of service. Affected versions include Firefox before 149, Firefox ESR before 140.9, Thunderbird before 149, and Thunderbird ESR before 140.9. The vulnerability was disclosed on March 24, 2026, and is rated moderate impact by Mozilla, with a CVSS v3.1 base score of 9.8 (Critical) as assessed by NVD (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
The root cause is a miscompilation error in Firefox's JIT (Just-In-Time) compiler within the JavaScript Engine, classified under CWE-843 (Access of Resource Using Incompatible Type / Type Confusion) and CWE-733 (Compiler Optimization Removal or Modification of Security-critical Code). When the JIT compiler incorrectly optimizes or generates native code for certain JavaScript constructs, it may produce type-confused memory accesses that bypass type safety guarantees enforced at the interpreter level. The vulnerability is network-exploitable with no privileges or user interaction required, as malicious JavaScript can be delivered via a crafted web page or HTML email. The bug was tracked internally as Mozilla Bug 2013560 and was discovered by a team of researchers (Evyatar Ben Asher, Keane Lucas, Nicholas Carlini, Newton Cheng, Daniel Freeman, Alex Gaynor, and Joel Weinberger) using Claude from Anthropic (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
Successful exploitation could allow a remote attacker to achieve arbitrary code execution or cause a denial of service within the context of the browser or email client process. The type confusion arising from JIT miscompilation may enable an attacker to read or write memory out of bounds, potentially bypassing browser security boundaries and accessing sensitive data processed by the affected application. In the context of Thunderbird, exploitation could be triggered via a malicious HTML email, broadening the attack surface beyond web browsing (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The vulnerability was discovered through AI-assisted security research using Anthropic's Claude model, which is a notable aspect of its discovery context (Mozilla Advisory Firefox 149).
firefox, firefox-esr, or thunderbird executables (e.g., cmd.exe, powershell.exe, /bin/sh, curl, wget) that are not part of normal browser operation.Mozilla has released patched versions addressing this vulnerability: Firefox 149, Firefox ESR 140.9, Thunderbird 149, and Thunderbird ESR 140.9. Users and administrators should update immediately to one of these versions. No configuration-based workaround is available; upgrading is the only definitive remediation. As an interim measure, organizations may consider restricting access to untrusted websites, enabling browser isolation technologies, or deploying endpoint detection and response (EDR) tools to monitor for exploitation attempts. Downstream Linux distributions including Red Hat, Debian, openSUSE, AlmaLinux, Rocky Linux, and Amazon Linux have also released updated packages (Mozilla Advisory Firefox 149, Mozilla Advisory ESR 140.9).
The vulnerability attracted notable attention due to its discovery method: it was found by a team of researchers using Anthropic's Claude AI model, making it one of the first publicly credited CVEs discovered with AI assistance in a major browser. VulnCheck published a blog post specifically discussing the Anthropic/Glasswing-credited CVEs, highlighting the significance of AI-assisted vulnerability research (VulnCheck Blog). Security news outlets including CyberSecurityNews and HealSecurity covered the Firefox 149 release, noting the 37 vulnerabilities patched and the AI-assisted discovery angle. Community discussion on Mastodon and security forums reflected interest in the implications of AI-driven bug hunting for the broader security research ecosystem.
Fix availability across major Linux distributions and their releases.
bookworm
thunderbird: 1:140.9.0esr-1~deb12u1
sid
thunderbird: 1:140.9.0esr-1
trixie
thunderbird: 1:140.9.0esr-1~deb13u1
bionic (esm-apps)
mozjs38
devel
firefox
jammy
thunderbird
noble
firefox
questing
firefox
resolute
firefox
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."