CVE-2026-8390Disclosure(mozilla / firefox)

MEDIUMCVSS 7.3 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch mozilla firefox systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-825

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • firefox

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-12); latest day: 2
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
firefox

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-12: 2Mentions · 2026-05-18: 1Mentions · 2026-06-22: 1Mentions · 2026-06-23: 2PoC Mentioned / Linked · 2026-05-18: 1Exploit Tool / Code · 2026-05-18: 1Patch / Workaround · 2026-05-12: 2Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-05-12: 2Technical Details · 2026-05-18: 1Technical Details · 2026-06-23: 105-1205-1806-2206-23
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
PoC
116.7%
General
116.7%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-05-122
Disclosure1Patch1
2026-05-181
PoC1
2026-06-221
Patch1
2026-06-232
Disclosure1General1
Full discourse6 posts
  • 情報の灯台@joho_no_todai
    Patch

    OpenAIとTrail of Bitsが共同で立ち上げたPatch the Planet。 初回5日間のスプリントで19のOSSプロジェクトから数百件のバグを発見し、64件のプルリクエストを送った。 GPT-5.5が見つけたFirefoxの脆弱性(CVE-2026-8390)はPwn2Own Berlin開催の2日前にMozillaがパッチを適用し、登録6チーム中5チームが撤退している。 AIが穴を見つける速度に、直す手が追いついていない。 報告を積むだけでなく、研究者がパッチまで仕上げてメンテナーに届ける設計が成果を出し始めた。 https://joho-todai.com/openai-daybreak-expansion-vulnerabilities-shortage/

    Post summary

    OpenAI’s GPT-5.5 uncovered CVE-2026-8390 in Firefox, which Mozilla patched two days before the Pwn2Own Berlin event; as a result, most competing teams withdrew.

    0501532.0K
    11.4K followersView on X
  • xvonfers@xvonfers
    Disclosure

    (CVE-2026-8390)[2038081]UAF in WASM https://hg-edge.mozilla.org/mozilla-central/rev/c4e56be1fb8eb25484f5663277ae00315dc7dc5a https://www.mozilla.org/en-US/security/advisories/mfsa2026-45/#CVE-2026-8390 Reported by OpenAI Preparedness, Bill Demirkapi

    Post summary

    CVE-2026-8390, a use‑after‑free in WebAssembly, has been disclosed with a source‑code reference and an associated Mozilla advisory indicating a patch is available.

    021796.0K
    5.0K followersView on X
  • Awesome Agents@awagents
    General

    OpenAI's GPT-5.5-Cyber found CVE-2026-8390 in Firefox's WebAssembly engine before Pwn2Own Berlin - five of six registered exploit entries withdrew. #Openai #Security Link in the first comment 👇 https://t.co/tJ2Q2newj8

    Post summary

    The post announces that OpenAI’s analysis discovered CVE-2026-8390 in Firefox’s WebAssembly engine before the Pwn2Own event, but offers no PoC, exploit code, active exploitation evidence, patch information, or detailed technical details.

    1001064
    841 followersView on X
  • Awesome Agents@awagents
    Disclosure

    New podcast episode: AI Patched Firefox Before Pwn2Own - OpenAI's Security Pivot OpenAI's GPT-5.5-Cyber found CVE-2026-8390 in Firefox's WebAssembly engine before Pwn2Own Berlin - five of six registered exploit entries withdrew. Full episode in the reply. #AI #Podcast https://t.co/v6qCmfcfjb

    Post summary

    The tweet announces that OpenAI’s AI tool identified CVE‑2026‑8390 in Firefox’s WebAssembly engine ahead of the Pwn2Own Berlin contest, but offers no PoC, exploit, or patch information.

    1000063
    841 followersView on X
  • dbugs@ptdbugs
    PoC

    Use-after-free in the JavaScript: WebAssembly component CVE: CVE-2026-8390 PT ID: PT-2026-40022 Vendor: Mozilla Product: Firefox CVSS: n/a Credits: OpenAI Preparedness, Bill Demirkapi Description: Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-8390 • https://bugzilla.mozilla.org/show_bug.cgi?id=2038081 • https://www.mozilla.org/security/advisories/mfsa2026-45/ PoC/Exploit: https://github.com/kiddo-pwn/ffffirefox #dbugs_vuln

    Post summary

    CVE-2026-8390 is a use‑after‑free flaw in Firefox’s WebAssembly JavaScript component, for which a PoC is publicly available and a patch was released in Firefox 150.0.3.

    01000300
    1.2K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🧨 Firefox 150.0.3 is a critical patch. Here's an overview: CVE‑2026‑8401 – sandbox escape in Profile Backup CVE‑2026‑8391 – priv‑esca‑like “other” JS engine bug CVE‑2026‑8390 – UAF in JS:WebAssembly CVE‑2026‑8389 – JIT miscompilation in JS JIT CVE‑2026‑8388 – wrong boundary checks in JS JIT Any one of these can pop your browser; together they’re a browser‑pwn trifecta. #Firefox #CVE‑2026‑8401 #CVE‑2026‑8391 #CVE‑2026‑8390 #CVE‑2026‑8389 #CVE‑2026‑8388 #BrowserSecurity #JIT #WebAssembly #JavaScript #DevSecOps https://nvd.nist.gov/vuln/detail/CVE-2026-8401 https://nvd.nist.gov/vuln/detail/CVE-2026-8391 https://nvd.nist.gov/vuln/detail/CVE-2026-8390 https://nvd.nist.gov/vuln/detail/CVE-2026-8389 https://nvd.nist.gov/vuln/detail/CVE-2026-8388

    Post summary

    Mozilla released Firefox 150.0.3 to patch five critical JavaScript and WebAssembly vulnerabilities (CVE‑2026‑8401 to CVE‑2026‑8388) with no active exploitation or PoC details reported.

    0001082
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmozillafirefox---

Explore more