#VU88580 Processor optimization removal or modification of security-critical code in Mozilla products - CVE-2024-3854
Published: April 16, 2024
Mozilla Firefox
Firefox ESR
Firefox for Android
Mozilla
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to incorrect optimization, when some code patterns in the JIT incorrectly optimized switch statements and generated code with out-of-bounds-reads. A remote attacker can abuse such behavior to execute arbitrary code on the system.