Mozilla patched a high-severity Firefox vulnerability, CVE-2026-10702, after researchers showed that visiting a single malicious webpage could trigger arbitrary code execution inside the browser’s sandboxed renderer process. The flaw was traced to the SpiderMonkey JavaScript engine, where JIT optimization involving Object.keys(), length, and prototype handling could lead to a use-after-free condition. Reported affected versions include Firefox stable releases from 147 through 151.0.2, while Firefox ESR 140.12 was not listed as affected.
Researchers at Nebula Security said the same bug could also be used against Tor Browser builds based on vulnerable Firefox versions, allowing compromise from a webpage visit alone. Nebula published exploit material and used the bug as the first stage of an IonStack exploit chain, pairing it with CVE-2026-43499 ("GhostLock"), a Linux kernel futex flaw, to obtain root on a supported ARM64 Android 17 Google build. Available reporting said there was no confirmed in-the-wild exploitation against users at the time of disclosure.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
As of July 28, 2026, the available primary-source record did not establish that CVE-2026-10702 had been exploited in the wild against users. This reflects the status of known exploitation at that date.
Nebula publicly released exploit material and demonstrated CVE-2026-10702 as the first stage of IonStack. The chain paired it with CVE-2026-43499, a Linux kernel futex flaw dubbed GhostLock, to achieve root on a supported ARM64 Android 17 Google build.
Nebula showed that the same Firefox flaw could also compromise Tor Browser builds that incorporated vulnerable Firefox versions. The exploit path relied on SpiderMonkey JIT optimization issues that could produce a use-after-free condition after a single webpage visit.
Mozilla fixed CVE-2026-10702 in Firefox 151.0.3 after Nebula Security's report. The affected range was described as stable Firefox releases 147 through 151.0.2, while Firefox ESR 140.12 was not listed as affected.
Nebula Security reported a high-severity Firefox JIT vulnerability, tracked as CVE-2026-10702, to Mozilla. The bug could be triggered by simply visiting a malicious webpage and allowed arbitrary code execution in Firefox's sandboxed renderer/content process.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cryptika.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.