CVE-2026-15718: Invalid pointer in the JavaScript: WebAssembly component
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.13 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 152.0.6 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.13 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.13
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-15718
- CVE-2026-15719
- CVE-2026-16349
- CVE-2026-16350
- CVE-2026-16362
- CVE-2026-16351
- CVE-2026-16352
- CVE-2026-16363
- CVE-2026-16353
- CVE-2026-16354
- CVE-2026-16368
- CVE-2026-16369
- CVE-2026-16355
- CVE-2026-16356
- CVE-2026-16357
- CVE-2026-16371
- CVE-2026-16374
- CVE-2026-16375
- CVE-2026-16377
- CVE-2026-16379
- CVE-2026-16358
- CVE-2026-16381
- CVE-2026-16383
- CVE-2026-16387
- CVE-2026-16390
- CVE-2026-16391
- CVE-2026-16359
- CVE-2026-16396
- CVE-2026-16405
- CVE-2026-16412
- CVE-2026-16360
- CVE-2026-16361
- CVE-2026-14899
Frequently Asked Questions
What is the severity of CVE-2026-15718?
The severity of CVE-2026-15718 is critical, rated at 9 out of 10.
What does CVE-2026-15718 affect?
CVE-2026-15718 affects the JavaScript WebAssembly component in Mozilla Firefox.
How do I fix CVE-2026-15718?
To fix CVE-2026-15718, update to Firefox version 152.0.6 or later.
Is there any known exploitation of CVE-2026-15718 in the wild?
Currently, there are no known attacks in the wild exploiting CVE-2026-15718.
What type of flaw is described by CVE-2026-15718?
CVE-2026-15718 is characterized as an invalid pointer vulnerability in the JavaScript WebAssembly component.