Firefox JIT arbitrary code execution security flaw (CVE-2026-10702)
Vulnerability
Summary
Hide ▲
Show ▼
Mozilla's Firefox 151.0.3 update closes CVE-2026-10702, a JIT flaw that let a malicious webpage trigger arbitrary code execution in the browser's renderer process. The vulnerable stable-release range spans Firefox 147 through 151.0.2, and Tor Browser releases built on those Firefox versions were also affected. Nebula Security says no extra user action was required beyond visiting the page. Public exploit material exists, but the available record does not establish in-the-wild user compromise.
Related Happenings
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation Wave
H score53
First: 18.02.2026 08:52
Last: 18.02.2026 08:52
Sources 1
About this happening:
CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
CISA KEV multi-product active exploitation wave (CVE-2020-7796)
Exploitation WaveAbout this happening: CISA expanded its KEV catalog with four actively exploited flaws, signaling a live exploitation wave across Chrome, TeamT5 ThreatSonar, Zimbra, and Windows Video Act...
Timeline
-
29.07.2026 14:57 2 articles · 2h ago
Malicious webpage can trigger Firefox JIT code execution
Initial DisclosureNebula Security said CVE-2026-10702 in Firefox can be triggered by simply visiting a malicious webpage with no additional user interaction, yielding arbitrary code execution in the browser's renderer process. Mozilla fixed the flaw in Firefox 151.0.3, and the same issue was said to affect Tor Browser releases built on vulnerable Firefox versions; the available record as of July 28, 2026 did not establish exploitation against users in the wild.
Show sources
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser — thehackernews.com — 29.07.2026 14:57
- Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser — thehackernews.com — 29.07.2026 14:57