CVE-2019-9791: Critical severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-9791?
CVE-2019-9791 is a vulnerability that allows the compilation of functions that can cause type confusions between arbitrary objects in Mozilla Firefox and Thunderbird.
What is the severity of CVE-2019-9791?
CVE-2019-9791 has a severity rating of critical.
How does CVE-2019-9791 affect Mozilla Firefox and Thunderbird?
CVE-2019-9791 affects Mozilla Firefox versions 66.0 and later, Mozilla Firefox ESR versions 60.6 and later, and Mozilla Thunderbird versions 60.6 and later.
How can I fix CVE-2019-9791?
To fix CVE-2019-9791, update Mozilla Firefox to version 66.0 or later, Mozilla Firefox ESR to version 60.6 or later, or Mozilla Thunderbird to version 60.6 or later.
Where can I find more information about CVE-2019-9791?
More information about CVE-2019-9791 can be found in the following references: [Link 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1530958), [Link 2](https://www.mozilla.org/en-US/security/advisories/mfsa2019-07/), [Link 3](https://www.mozilla.org/security/advisories/mfsa2019-07/).