CVE-2016-9896: Mozilla Firefox

High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.

Affected products

  • Mozilla Firefox: before 50.1.0 (fixed in 50.1.0)

Published 2018-06-11. Last modified 2026-06-17.