CVE-2019-17026: Mozilla Firefox And Thunderbird Type Confusion Vulnerability
High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 46.3% chance of exploitation in the next 30 days.
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
Affected products
- Canonical Ubuntu Linux: version 16.04 only
- Mozilla Firefox: before 68.4.1 (fixed in 68.4.1); before 72.0.1 (fixed in 72.0.1)
- Mozilla Thunderbird: before 68.4.1 (fixed in 68.4.1)
Published 2020-03-02. Last modified 2026-06-17.