Firefox SpiderMonkey JIT Type Confusion (CVE-2026-10702)
Published: 2026-09-03 • Researcher: Nebula Security (NebuSec / CyberMeowfia)
- Severity
- Medium
- CVE
- CVE-2026-10702
- Category
- binary
- Affected product
- Mozilla Firefox (SpiderMonkey JIT engine)
- Affected versions
- Firefox on Android (pre-patch)
- Disclosed
- 2026-09-03
- Patch status
- Unverified
References
Archive entry
intelseclab/poc-archiveOn this page
Metadata
| Field | Value |
|---|---|
| Date Added | 2026-09-03 |
| Author / Researcher | Nebula Security (NebuSec / CyberMeowfia) |
| CVE / Advisory | CVE-2026-10702 |
| Category | binary |
| Severity | Medium |
| CVSS Score | 4.3 |
| Status | PoC |
| Tags | Firefox, SpiderMonkey, JIT, type confusion, browser, sandbox escape, IonStack, JavaScript |
Affected Target
| Field | Value |
|---|---|
| Software / System | Mozilla Firefox (SpiderMonkey JIT engine) |
| Versions Affected | Firefox on Android (pre-patch) |
| Language / Platform | HTML, JavaScript |
| Authentication Required | No (visit malicious page) |
| Network Access Required | Remote (browser navigation) |
Summary
CVE-2026-10702 is a type confusion vulnerability in the Firefox SpiderMonkey JIT compiler. Nebula Security developed a browser-based exploit as part of their IonStack chain (Firefox sandbox escape stage). The exploit is delivered as an HTML page that triggers JIT compilation bugs to achieve code execution within the browser renderer. As a standalone bug, CVSS is 4.3 (Medium); its significance increases when chained with kernel exploits for full device compromise.
Environment / Lab Setup
Browser: Mozilla Firefox (Android, pre-patch)
Target: Pixel 10 Pro / blazer (for IonStack chain)
Delivery: HTML page loaded in browserReferences
Notes
Part of Nebula Security IonStack chain (CVE-2026-10702 Firefox sandbox escape + CVE-2026-43499 kernel LPE = browser-to-root). Auto-ingested from https://github.com/NebuSec/CyberMeowfia on 2026-09-03.
| |