CVE-2026-8390: Use-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.3 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 150.0.3
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-8390?
CVE-2026-8390 has a high severity rating due to the potential exploitation of a use-after-free vulnerability in the JavaScript: WebAssembly component.
How do I fix CVE-2026-8390?
To fix CVE-2026-8390, update Mozilla Firefox to version 150.0.3 or later.
What are the effects of CVE-2026-8390 if exploited?
If exploited, CVE-2026-8390 can lead to remote code execution or application crashes.
Which versions of Firefox are affected by CVE-2026-8390?
CVE-2026-8390 affects Firefox versions prior to 150.0.3.
Is there a workaround for CVE-2026-8390?
There is no effective workaround for CVE-2026-8390; the best action is to update to the fixed version.