What the vulnerability does

01Description

Use-after-free in the JavaScript Engine component. This vulnerability was fixed in Firefox 149 and Thunderbird 149.

Key dates

02Disclosure timeline

March 24, 2026 CVE published
April 13, 2026 Record updated