[CVE-2026-10702] IonStack Part I: Unsound IonBanana Peel in Ion Compiler, Slipping Through Firefox's SpiderMonkey JIT
nebusec.ai | vulnerability | High | CVE-2026-10702 | #rce | #featured | #vulnerability-research | #browser-security | #firefox | #jit | #spidermonkey | #cve-2026-10702 | #nebusec | #tor-browser
Summary
NebuSec details CVE-2026-10702, a SpiderMonkey Ion JIT miscompilation that can lead to arbitrary code execution in the Firefox content process and also affects Tor Browser. Mozilla fixed the issue in Firefox 151.0.3.
Why it matters
A JIT miscompilation reaches arbitrary code execution in the Firefox content process and also affects Tor Browser, underscoring the residual risk in heavily audited JavaScript engines.
- Vendor
- Mozilla
- Product
- Firefox / SpiderMonkey
- Affected versions
- Firefox < 151.0.3
- Published
- Collected
Skip to content