CVE-2020-26950: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 42.3% chance of exploitation in the next 30 days.
In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
Affected products
- Mozilla Firefox: before 82.0.3 (fixed in 82.0.3)
- Mozilla Firefox ESR: before 78.4.1 (fixed in 78.4.1)
- Mozilla Thunderbird: before 78.4.2 (fixed in 78.4.2)
Published 2020-12-09. Last modified 2026-06-17.