CVE-2019-11707: Mozilla Firefox and Thunderbird Type Confusion Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2022-05-23. EPSS: 37.7% chance of exploitation in the next 30 days.
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.
Affected products
- Mozilla Firefox: before 60.7.1 (fixed in 60.7.1); before 67.0.3 (fixed in 67.0.3)
- Mozilla Thunderbird: before 60.7.2 (fixed in 60.7.2)
Published 2019-07-23. Last modified 2026-06-17.