CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Firefox. Public exploit code or proof-of-concept references have been detected in its references. Its EPSS score suggests a 19.8% probability of exploitation in the next 30 days.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack replacement (OSR). This allows for possible arbitrary reading and writing of objects during an exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
Related CVEs
Other vulnerabilities affecting the same vendor(s)