CVE-2016-9896: Mozilla Firefox
High severity, CVSS 8.1. EPSS: 2% chance of exploitation in the next 30 days.
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
Affected products
- Mozilla Firefox: before 50.1.0 (fixed in 50.1.0)
Published 2018-06-11. Last modified 2026-06-17.