CVE-2026-8389: JIT miscompilation in the JavaScript Engine: JIT component
Published May 12, 2026
·Updated
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<150.0.3
Mozilla Firefox<150.0.3
150.0.3
Mozilla Firefox<150.0.3
Event History
May 12, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Oct 31, 58347
Event
via FIRST·09:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-8389?
CVE-2026-8389 has been classified as a moderate severity vulnerability due to the potential for JIT miscompilation in the JavaScript Engine.
2
How do I fix CVE-2026-8389?
To fix CVE-2026-8389, update your Firefox browser to version 150.0.3 or later.
3
What does CVE-2026-8389 affect?
CVE-2026-8389 affects the JIT component of the JavaScript Engine within Firefox prior to version 150.0.3.
4
Is there a workaround for CVE-2026-8389?
There are no official workarounds available for CVE-2026-8389, so upgrading to the patched version is recommended.
5
When was CVE-2026-8389 discovered?
CVE-2026-8389 was disclosed in the cybersecurity advisory released by Mozilla.