CVE-2026-8390: Use-after-free in the JavaScript: WebAssembly component
Published May 12, 2026
·Updated
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.
Affected Software
3 affected componentsFixes available
Mozilla Firefox<150.0.3
Mozilla Firefox<150.0.3
150.0.3
Mozilla Firefox<150.0.3
Event History
May 12, 2026
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
Description
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Oct 13, 58358
Event
via FIRST·03:42 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-8390?
CVE-2026-8390 has a high severity rating due to the potential exploitation of a use-after-free vulnerability in the JavaScript: WebAssembly component.
2
How do I fix CVE-2026-8390?
To fix CVE-2026-8390, update Mozilla Firefox to version 150.0.3 or later.
3
What are the effects of CVE-2026-8390 if exploited?
If exploited, CVE-2026-8390 can lead to remote code execution or application crashes.
4
Which versions of Firefox are affected by CVE-2026-8390?
CVE-2026-8390 affects Firefox versions prior to 150.0.3.
5
Is there a workaround for CVE-2026-8390?
There is no effective workaround for CVE-2026-8390; the best action is to update to the fixed version.