CVE-2020-26950

HIGH

Firefox MCallGetProperty Write Side Effects Use After Free Exploit

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-26950. PoCs published by 360 ESG Vulnerability Research Institute, maxpl0it, timwr, including Metasploit module exploits/multi/browser/firefox_jit_use_after_free.

AI-analyzed exploit summary This Metasploit module exploits CVE-2020-26950, a use-after-free vulnerability in Firefox's JIT compiler via MCallGetProperty opcode manipulation. It sprays ArgumentsData structures to achieve arbitrary code execution by overwriting JIT memory regions.

Description

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

Exploits (1)

metasploit WORKING POC MANUAL
by 360 ESG Vulnerability Research Institute, maxpl0it, timwr · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/browser/firefox_jit_use_after_free.rb

This Metasploit module exploits CVE-2020-26950, a use-after-free vulnerability in Firefox's JIT compiler via MCallGetProperty opcode manipulation. It sprays ArgumentsData structures to achieve arbitrary code execution by overwriting JIT memory regions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: Firefox < 82.0.3, Firefox ESR < 78.4.1, Thunderbird < 78.4.2
No auth needed
Prerequisites: Firefox must be run with MOZ_DISABLE_CONTENT_SANDBOX environment variable set
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.mozilla.org/show_bug.cgi?id=1675905
Vendor Advisory x_refsource_confirm
https://www.mozilla.org/security/advisories/mfsa2020-49/

Scores

CVSS v3 8.8
EPSS 0.4260
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-416
Status published
Products (3)
mozilla/firefox < 82.0.3
mozilla/firefox_esr < 78.4.1
mozilla/thunderbird < 78.4.2
Published Dec 09, 2020
Tracked Since Feb 18, 2026