CVE-2026-2796 is a critical type-confusion vulnerability caused by JIT miscompilation and incorrect optimization in the JavaScript WebAssembly component of Firefox and Thunderbird. The flaw arises during WebAssembly import handling, where optimization of Function.prototype.call.bind wrappers can unwrap and substitute an inner target function without verifying that the target’s actual type signature matches the WebAssembly import’s declared signature. In the vulnerable logic, the optimized callable can later be returned and invoked as though it had the importing module’s declared type, allowing a function reference originating from a different WebAssembly context and incompatible signature to be used with call_ref. This bypasses the normal JavaScript interop conversion path and causes raw WebAssembly stack values to be interpreted under the wrong type, resulting in type confusion. Public analysis indicates this confusion can be developed into classical exploitation primitives including address disclosure, fake object creation, arbitrary read, arbitrary write, and ultimately code execution within the JavaScript engine. Mozilla fixed the issue in Firefox 148 and Thunderbird 148.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a real proof-of-concept exploit for CVE-2026-12295, a Firefox UXSS/origin-confusion issue in which a compromised content process forges a PNecko::PDocumentChannel constructor carrying nsDocShellLoadState with SrcdocData set alongside a non-about:srcdoc URI. On vulnerable Firefox builds, the parent process accepts the forged load state and docshell serves attacker-controlled srcdoc HTML as the document at the forged URI's origin, yielding same-origin access to victim resources. Repository structure: the core exploit logic is split across srcdoc.html and forge.py. forge.py constructs a byte-accurate forged IPC message based on a captured real DocumentChannel message template, serializing a target URI of http://localhost:8778/nav.html and embedding attacker HTML that fetches /secret.txt and exfiltrates it to http://127.0.0.1:8778/exfil. It outputs forge.bin and forge.json for runtime use. srcdoc.html is the browser-side exploit page; it loads wasm-bytes.js, uses WebAssembly-based arbitrary read/write and call primitives (stage-1 exploit support) to locate Firefox/XUL structures in memory, opens an about:blank popup to obtain a same-process top-level BrowsingContext, patches runtime fields into the forged message, constructs a real IPC::Message object, writes the forged payload into it, and sends it through MessageChannel::Send on the live content-parent channel. Supporting files: wasm-bytes.js contains raw WebAssembly byte arrays implementing the memory corruption primitives used by srcdoc.html. parse_dc.py is a helper/parser for captured PDocumentChannel constructor messages and is used by forge.py for validation and reverse engineering. mdrive2.py is a Marionette automation harness that launches a local Firefox Nightly build, waits, and navigates to the exploit page. irun is a zsh orchestration script that prepares the profile, launches the harness, attaches LLDB to the Firefox parent process, and collects evidence from logs. profile.user.js sets permissive Firefox prefs needed for the demo. nav.html and secret.txt are demo fixtures representing the victim-origin page and sensitive data. Capabilities: the exploit does not achieve initial code execution by itself; it assumes an already compromised Firefox content process. Given that prerequisite, it weaponizes the browser IPC path to perform a cross-origin document load confusion, resulting in UXSS, same-origin reads, and exfiltration. The included payload is operational and demonstrates theft of a same-origin secret plus visible page takeover ('PWNED at <origin>').
Repository is a real exploit PoC for CVE-2026-74939, a Firefox content-to-parent privilege escalation / sandbox escape. The exploit abuses insufficient validation of nsDocShellLoadState.RemoteTypeOverride in content->parent IPDL traffic so a compromised content process can force a navigation into the privilegedabout process. The repo is not a generic framework module; it is a standalone research PoC with exploit page, message builder, parsers, and local automation. Core exploit flow: forge.py constructs a byte-accurate PNecko::PDocumentChannel constructor message based on a captured legitimate DocumentChannel message. It modifies key fields to set URI=about:blank, RemoteTypeOverride=privilegedabout, TriggeringPrincipal and PrincipalToInherit to null principals, and patches runtime values such as browsing context IDs and TriggeringRemoteType. The output is split into head/tail base64 blobs in forge.json so privesc.html can splice in the live remote type string at runtime. The main exploit is privesc.html. It loads wasm-bytes.js, which contains prebuilt WebAssembly modules used to obtain stage-1 arbitrary read/write and indirect native-call primitives. The page fetches /forge.json, opens a popup to about:blank to obtain a top-level browsing context in the compromised process, leaks Firefox/XUL pointers and state from memory, derives the current ContentChild remote type, patches the forged payload with live routing and browsing context values, allocates native memory with operator new, constructs an IPC::Message, copies the forged payload with Pickle::WriteBytes, and finally invokes MessageChannel::Send on the real IPC channel. This avoids raw socket writes and leverages the browser’s native mojo/IPDL send path. Supporting files: parse_dc.py is a sequential parser for captured PDocumentChannel constructor messages and is used by forge.py for template parsing and self-verification. extract_fields.py and scan_sentinels.py are analysis utilities for reverse engineering and mapping IPDL field offsets in captured messages. forge.json is a sample generated message template/metadata artifact. mdrive.py and mdrive2.py are Marionette harnesses that launch a custom Firefox Nightly build, connect to Marionette on 127.0.0.1:2828, and navigate to the exploit page. irun is a zsh orchestration script that launches the harness, attaches lldb to the Firefox parent process, sets a breakpoint on NeckoParent::RecvPDocumentChannelConstructor, and collects MOZ_LOG evidence showing the process switch. profile.user.js contains Firefox prefs to make the test environment permissive and reproducible. Exploit capability: this is a stage-2 browser sandbox escape / privilege escalation, not initial RCE. It assumes prior code execution in a Firefox content process (README references chaining after CVE-2026-2796). Successful exploitation causes the parent to honor a forged privilegedabout remote type override for an about:blank load, violating process isolation and moving the page into a privileged process. The repo contains operational exploit code and local test harnessing, but payload customization is limited and build-specific offsets are hardcoded.
This repository is a single-file GitHub Actions-based proof of concept for CVE-2026-2796. It is not a full exploit framework or weaponized exploit; instead, it automates reproduction of a SpiderMonkey/WebAssembly type confusion or optimization bypass condition using Mozilla's standalone js shell. Structure: the repository contains only .github/workflows/blank.yml. That workflow defines a matrix job testing two versions: Firefox 147.0 (expected vulnerable) and 148.0.2 (expected patched). The workflow installs dependencies, downloads the corresponding js shell from Mozilla archive infrastructure, generates a JavaScript PoC on the fly, and executes it. Exploit capability: the generated JavaScript constructs two WebAssembly modules. Module B exports a simple identity function. That function is wrapped with Function.prototype.call.bind, then imported into Module A, which invokes it through a Wasm ref.func/call_ref-related path. The intended effect is to demonstrate that on vulnerable builds the optimization incorrectly bypasses the bound-call semantics and directly invokes the raw Wasm function, returning the original input 1337. On patched builds, argument handling changes and the result is 0. This makes the repository a reproduction PoC for vulnerability verification and regression testing, not a post-exploitation tool. Operationally, the workflow reaches out to archive.mozilla.org and ftp.mozilla.org to fetch jsshell-linux-x86_64.zip, extracts jsshell/js, writes repro-cve-2026-2796.js, and runs it locally. There are no reverse shells, callbacks, credential theft routines, persistence mechanisms, or lateral movement features. The main security-relevant observable behavior is local execution of a crafted Wasm/JavaScript sequence against specific SpiderMonkey builds to confirm vulnerable behavior.
The repository contains a single GitHub Actions workflow, .github/workflows/blank.yml, which serves as the entire proof-of-concept. It is not a traditional standalone exploit program; instead, it automates environment setup, downloads Mozilla's JavaScript shell for Firefox versions 147.0 and 148.0.2, generates a JavaScript file named stage2.js, and executes it. The exploit logic is embedded directly inside the workflow as a heredoc. The JavaScript uses WebAssembly to construct two core exploitation primitives commonly used in browser/JIT/engine exploitation: addrof, which obtains an address-like representation of a JavaScript object, and fakeobj, which attempts to turn an integer/address back into an object reference. It does this by creating WebAssembly modules that reinterpret externref and i64 values through imported/exported function calls and call_ref usage. The script then tests these primitives against a sample object and prints a verdict indicating whether each primitive appears to work. Operationally, this is a proof-of-concept for memory corruption research rather than a complete weaponized exploit. There is no reverse shell, command execution payload, persistence, or post-exploitation logic. Its purpose is to validate whether the targeted engine behavior can produce exploitation building blocks. Because the repository consists only of a CI workflow and generated script, the structure is minimal: one YAML workflow file containing shell commands and embedded JavaScript exploit code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical Firefox JavaScript/WebAssembly JIT miscompilation vulnerability that can be exploited (in a reduced-security test setup) to achieve arbitrary read/write and code execution via type confusion.
A critical Firefox vulnerability described as a just-in-time (JIT) miscompilation in the JavaScript WebAssembly component.
A vulnerability referenced only by CVE ID in the context of reverse engineering an exploit for it; no additional details are provided in the content.
A now-patched high-severity Firefox vulnerability for which Anthropic reports Claude generated a working exploit in a reduced-security testing environment (not a full-chain sandbox escape).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.