Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150 and Thunderbird 150.
https://www.securityweek.com/claude-mythos-finds-271-firefox-vulnerabilities/
https://www.mozilla.org/security/advisories/mfsa2026-33/