
(CVE-2026-8388)[2036978]Incorrect boundary conditions in JIT https://hg-edge.mozilla.org/mozilla-central/rev/f5e01e65b75a28326c9cb3c858f803b2fb6d828a (CVE-2026-8389)[2036983]JIT miscompilation https://hg-edge.mozilla.org/mozilla-central/rev/f40113af5ca58bb949fe7c19f58b82ff1723b343 (CVE-2026-8401)[2038679]SBX escape in the Profile Backup https://hg-edge.mozilla.org/mozilla-central/rev/ef49b255ce2a13b89743a1daf85526323a5d38ee https://www.mozilla.org/en-US/security/advisories/mfsa2026-45/ Reported by @ggwhyp
Post summary
Mozilla has publicly disclosed three CVEs involving JIT and SBX vulnerabilities, providing direct links to the relevant code changes and an advisory, but the text contains no evidence of PoC, exploit tools, or active exploitation.

