CVE-2026-8389 is a JIT miscompilation vulnerability in Firefox's JavaScript engine, specifically in the JIT component. The provided content indicates that incorrect code generation or optimization in the JIT compiler can lead to unsafe execution behavior. No further technical detail about the specific vulnerable function, optimization pass, or trigger condition is available in the provided material. Mozilla fixed the issue in Firefox 150.0.3.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a standalone browser exploit PoC for CVE-2026-8389, a SpiderMonkey BaselineJIT pcOffset truncation bug affecting the eager off-thread baseline compilation path. Structure is minimal: README.md documents the root cause and affected code path; poc-win-rce.html is the main exploit driver; primer.js is a stub used for the first-stage priming request; payload.js is a very large Git LFS-tracked JavaScript blob (~179 MB) that likely contains the real exploitation logic; server.py is a custom HTTP server that alternates /payload.js responses between primer.js and payload.js to support a two-page-load/JitHints priming strategy. The exploit is not just a detector. The HTML PoC explicitly warms the engine, repeatedly calls exploit(false)/exploit(true), waits for a confusion condition, then proceeds through staged exploitation: Stage 0 confirms confusion; Stage 1 builds read/write primitives and discovers heap/module state; later stages identify PE/JIT structures, hijack a JIT code pointer, and invoke shellcodeCarrier() to execute native code. Embedded comments state the intended result is Windows RCE by launching calc.exe. The code also includes mitigation-aware logic, checking whether JIT RWX is available and falling back to .data-based shellcode placement if W^X is enforced. Network behavior is simple and fingerprintable: the browser fetches http://localhost:8099/payload.js, sends logs to /log, sends stage beacons to /beacon?c=...&m=..., and signals completion via /signal?rce=complete. The Python server listens on port 8099, serves local files from the repository directory, resets state when an HTML page is loaded, and alternates /payload.js between primer and exploit content. Overall, this is an operational local-hosted exploit kit for a Firefox/SpiderMonkey JIT vulnerability, with a browser-delivered trigger and a Windows-focused native code execution payload.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.