What the vulnerability does

01Description

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.

Key dates

02Disclosure timeline

April 21, 2026 CVE published
May 26, 2026 Record updated