CVE-2019-17026: high-severity vulnerability in Mozilla Firefox
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
The Firefox JavaScript engine (IonMonkey) incorrectly handles how it tracks memory locations when setting array elements, causing it to confuse different data types. This can allow attackers to run malicious code on your computer.
IonMonkey JIT compiler exhibits incorrect alias analysis (CWE-843) during array element writes, leading to type confusion that permits memory corruption. The vulnerability is exploitable through malicious JavaScript in web content without user interaction beyond visiting a compromised page; successful exploitation enables arbitrary code execution with the privileges of the Firefox process.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.