CVE-2026-10702
EPSS 0.7%Credible researcher disclosure + exploit chain claims, but no PoC public, not KEV-listed, unclear real-world impact.
What: JIT miscompilation in Firefox's IonMonkey JavaScript engine; instruction-modeling flaw affecting Firefox <151.0.3 (EPSS 0.002, low base score).
Why it matters: Firefox patched promptly (v151.0.3); security researcher disclosed "IonStack" chain pairing this CVE with CVE-2026-43499 for Android browser-to-kernel exploit. No public PoC yet, not KEV-listed. Chatter emphasizes severity of exploit chain rather than standalone CVE risk.
Where it's seen: Researcher posts detailing technical nature (IonMonkey flaw); Android exploit chain claims circulating; no vendor emergency advisory beyond standard patch release; low engagement outside specialist circles.
RISK: MODERATE — Firefox patched; exploit chain disclosed but PoC withheld; modest EPSS score.
Description
JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3.