Mozilla has issued a critical patch for Firefox, Firefox ESR, and Thunderbird after a security issue was discovered at the Tianfu Cup 2020 International Cybersecurity Contest. The security issue has been assigned CVE-2020-26950 which has the reserved status. In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. In a worst case scenario this could allow for a remote code execution (RCE) attack.”]

