What the vulnerability does

01Description

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.

Key dates

02Disclosure timeline

July 21, 2026 CVE published
July 22, 2026 Record updated