LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-4702 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: March 24, 2026

Firefox - Remote Code Execution

Published: March 24, 2026Updated: March 24, 2026Remote Exploitable

Overview

Firefox < 149 and Firefox ESR < 140.9 contain a code execution vulnerability caused by JIT miscompilation in the JavaScript Engine, letting attackers execute arbitrary code, exploit requires crafted JavaScript code execution.

Severity & Score

Severity: Critical
CVSS Score: 9.8

Impact

Attackers can execute arbitrary code remotely via crafted JavaScript, potentially compromising the user's system.

Mitigation

Update to Firefox 149 or later and Firefox ESR 140.9 or later.

Details

CVE ID
CVE-2026-4702
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
modified

CWE

  • CWE-843

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H