Security Advisory

CVE-2019-17026

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-03-02 04:05:03
Last updated 2025-10-21 23:35:50
Assigner mozilla
State PUBLISHED

Description

Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.