The record
Written from the 1 report below. Nothing here is unsourced.
- Nebula Security researchers disclosed a critical Firefox JIT vulnerability enabling remote code execution via malicious webpages, affecting Firefox versions 147 through 151.0.2 as well as Tor Browser.
- Mozilla has released a fix in Firefox 151.0.3, but Tor Browser users must await an upstream Tor Project update or manually verify mitigation.
- A public proof of concept exists and the flaw is rated high severity (CVSS 7.8), though exploitation in the wild has not yet been confirmed.
- The weakness (CWE-416, use-after-free) sits in JIT compiler logic, making it a prime target for browser-exploit chains and sandbox escapes.
- Coverage so far originates from a single cybersecurity outlet (The Hacker News), while an unrelated NVD entry for CVE-2026-43499 (a Linux kernel rtmutex fix) appears conflated in the source data.
- Users and enterprises should prioritize immediate patching; Tor users should watch for tor-project advisories.
- Next steps include tracking whether CVE-2026-10702 is added to KEV and monitoring for wild exploitation reports.
What to watch next
- Update Firefox to 151.0.3 immediately; Tor Browser users must await Tor Project patch.
- Watch for Mozilla SFSA or CISA KEV addition within 7-14 days.
- Monitor for follow-up reports of in-the-wild exploitation or sandbox escapes.
Why it matters3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Firefox users (versions 147–151.0.2) and Tor Browser remote code execution risk· immediate
- Organizations using Firefox/Tor endpoints patch required· days
- Mozilla reputational and maintenance burden· weeks
Coverage1
1 report
English national1
Filed from India ×1, United States ×1
Named Android 17 · Linux · Linux kernel · Mozilla · Eten Zou · Firefox · IonStack · Nebula Security · Tor Browser
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
