CVE-2016-5287: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

Affected products

  • Mozilla Firefox: before 49.0.2 (fixed in 49.0.2)

Published 2018-06-11. Last modified 2026-06-17.