CVE-2023-6866: Mozilla Firefox

High severity, CVSS 8.8. EPSS: 0.7% chance of exploitation in the next 30 days.

TypedArrays can be fallible and lacked proper exception handling. This could lead to abuse in other APIs which expect TypedArrays to always succeed. This vulnerability affects Firefox < 121.

Affected products

  • Mozilla Firefox: before 121.0 (fixed in 121.0)

Published 2023-12-19. Last modified 2026-06-17.