Download Firefox

Firefox is no longer supported on Windows 8.1 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox is no longer supported on macOS 10.14 and below.

Please download Firefox ESR (Extended Support Release) to use Firefox.

Firefox Privacy Notice

Mozilla Foundation Security Advisory 2016-71

Crash in incremental garbage collection in JavaScript

Announced
August 2, 2016
Reporter
Jukka Jylänki
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 48

Description

Security researcher Jukka Jylänki reported a use-after-free in JavaScript caused by how objects and pointers are handled during incremental garbage collection in some circumstances working with object groups. When triggered, this causes a potential exploitable crash but is mitigated by the difficulties in controlling the crash and its output.

References