The IonMonkey just-in-time (JIT) compiler can leak an...
Critical severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Nov 25, 2025
Description
Published by the National Vulnerability Database
Apr 26, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Nov 25, 2025
The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.
References