CVE-2019-11707 is a type confusion vulnerability in Mozilla Firefox, Firefox ESR, and Thunderbird in JavaScript object handling related to Array.pop. When JavaScript manipulates objects in a way that triggers the flawed Array.pop behavior, the engine can enter an invalid type state and crash in an exploitable manner. The vulnerability was observed in targeted in-the-wild attacks. Available reporting indicates the flaw could be leveraged for universal cross-site scripting and, when combined with an additional sandbox escape, for remote code execution on the underlying system.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
The repository contains a short README and one 56 KB self-contained HTML/JavaScript exploit. `exploit.html` implements a staged browser-to-SYSTEM chain: it parses stage/run/retry parameters, performs low-level JavaScript memory manipulation consistent with an IonMonkey native-code-execution attempt for CVE-2019-11707, and uses a privileged `Prompt:Open` message path intended to reach the Firefox parent process (CVE-2019-11708). It then includes a large Base64-embedded Donut x64 payload described as a CVE-2021-1732 Windows privilege-escalation executable. The stated final action is an elevated `cmd.exe /k whoami` command prompt. It has retry and pointer-drift checks, restores modified class pointers on exceptions, and contains optional localhost-only hold/signaling instrumentation; it does not require external exploit hosting, fixed module bases, or profile modifications according to its comments. The README only links to external research and a demonstration video.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote code execution vulnerability in Mozilla Firefox that allowed attackers to execute arbitrary code on the victim's system. It was exploited in the wild to deliver persistent macOS malware (OSX.NetWire.A) to targeted users, including those in the cryptocurrency sector.
A critical Firefox type confusion vulnerability in JavaScript Array.pop that can lead to an exploitable crash and potentially remote code execution or universal cross-site scripting. Mozilla states it is being abused in targeted attacks in the wild.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.