CVE-2024-3858: Mozilla Firefox

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.

Affected products

  • Mozilla Firefox: before 125.0 (fixed in 125.0)

Published 2024-04-16. Last modified 2026-06-17.