CVE-2024-3862: Mozilla Firefox

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.

Affected products

  • Mozilla Firefox: before 125.0 (fixed in 125.0)

Published 2024-04-16. Last modified 2026-06-17.