JIT miscompilation in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.
https://thehackernews.com/2026/03/anthropic-finds-22-firefox.html
https://www.theregister.com/2026/03/06/firefox_bugs_anthropic_ai/
https://github.com/SneakyNachos/CVE-2026-4692-trust-me-im-in-rdm
https://github.com/SneakyNachos/CVE-2026-12295-UXXS-in-my-wasm
https://github.com/SneakyNachos/CVE-2026-74939-escape-the-mac-n-cheese-box
https://github.com/SneakyNachos/CVE-2026-15718-who-put-ptrs-in-my-wasm
https://github.com/SneakyNachos/CVE-2026-2796-and-CVE-2026-2768-escape-the-wasm-box
https://github.com/SneakyNachos/CVE-2026-2796-escape-wasm-by-using-wasm
https://github.com/AndrewAltimit/exploits
https://www.mozilla.org/security/advisories/mfsa2026-16/
https://www.mozilla.org/security/advisories/mfsa2026-13/
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-2796.json
https://bugzilla.redhat.com/show_bug.cgi?id=2442301