First published: Tue Jan 07 2025(Updated: )
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <134 | |
Firefox ESR | <128.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The REDHAT-BUG-2336188 vulnerability has a critical severity rating due to its potential to cause use-after-free conditions.
To fix REDHAT-BUG-2336188, update to Firefox version 134 or later, or Firefox ESR version 128.6 or later.
REDHAT-BUG-2336188 can lead to cross-compartment access issues that may compromise user data.
REDHAT-BUG-2336188 affects Firefox versions earlier than 134 and Firefox ESR versions earlier than 128.6.
REDHAT-BUG-2336188 is not specific to any operating system but affects the mentioned browser versions across all platforms.