CVE-2020-26950: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 42.3% chance of exploitation in the next 30 days.

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

Affected products

  • Mozilla Firefox: before 82.0.3 (fixed in 82.0.3)
  • Mozilla Firefox ESR: before 78.4.1 (fixed in 78.4.1)
  • Mozilla Thunderbird: before 78.4.2 (fixed in 78.4.2)

Published 2020-12-09. Last modified 2026-06-17.