CVE-2026-4702 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: March 24, 2026
Firefox - Remote Code Execution
Published: March 24, 2026Updated: March 24, 2026Remote Exploitable
Overview
Firefox < 149 and Firefox ESR < 140.9 contain a code execution vulnerability caused by JIT miscompilation in the JavaScript Engine, letting attackers execute arbitrary code, exploit requires crafted JavaScript code execution.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Attackers can execute arbitrary code remotely via crafted JavaScript, potentially compromising the user's system.
Mitigation
Update to Firefox 149 or later and Firefox ESR 140.9 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-4702
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- undefined
- Status
- modified
CWE
- CWE-843
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H