Back

HIGH

Type Confusion in Async Generators in Javascript Engine

Published Sep 6, 2024

Description

An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Sep 6, 2024
Updated Oct 30, 2025
Reserved Aug 9, 2024
CISA Vulnrichment
Updated Sep 6, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 6, 2024