CVE-2019-17026
Mozilla Firefox ESR, Mozilla Thunderbird, Mozilla Firefox
Published 2 Mar 2020 · updated 17 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
References
- packetstormsecurity.com/files/162568/Firefox-72-IonMonkey-JIT-Type-Confusion.html · Exploit, Third Party Advisory, VDB Entry
- bugzilla.mozilla.org/show_bug.cgi?id=1607443 · Issue Tracking
- security.gentoo.org/glsa/202003-02 · Third Party Advisory
- usn.ubuntu.com/4335-1/ · Third Party Advisory
- www.mozilla.org/security/advisories/mfsa2020-03/ · Vendor Advisory
- www.mozilla.org/security/advisories/mfsa2020-04/ · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-17026 · US Government Resource