← back

CVE-2026-10702

EPSS 0.7%
hype MIXED · 52 hack

Credible researcher disclosure + exploit chain claims, but no PoC public, not KEV-listed, unclear real-world impact.

What: JIT miscompilation in Firefox's IonMonkey JavaScript engine; instruction-modeling flaw affecting Firefox <151.0.3 (EPSS 0.002, low base score).

Why it matters: Firefox patched promptly (v151.0.3); security researcher disclosed "IonStack" chain pairing this CVE with CVE-2026-43499 for Android browser-to-kernel exploit. No public PoC yet, not KEV-listed. Chatter emphasizes severity of exploit chain rather than standalone CVE risk.

Where it's seen: Researcher posts detailing technical nature (IonMonkey flaw); Android exploit chain claims circulating; no vendor emergency advisory beyond standard patch release; low engagement outside specialist circles.

RISK: MODERATE — Firefox patched; exploit chain disclosed but PoC withheld; modest EPSS score.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 6/25/2026, 8:39:31 AM

Description

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.