In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.
https://www.mozilla.org/security/advisories/mfsa2020-49/
https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-19474