What the vulnerability does

01Description

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

Key dates

02Disclosure timeline

February 24, 2026 CVE published
April 13, 2026 Record updated