Cybersecuritynews
Single-Character Typo Causes 0-Day RCE Vulnerability in Firefox
First seen 18 Feb 2026, 20:21 UTC
•

•64.2
Export
Article Content
Browse articles
A critical Remote Code Execution (RCE) vulnerability in Mozilla Firefox was identified due to a single-character typo in the SpiderMonkey JavaScript engine’s WebAssembly garbage collection code. The error occurred when a developer mistakenly typed '&' instead of '|', leading to the flaw's discovery by security researcher Erge while reviewing the Firefox 149 Nightly source code.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Timeline
2026-02-18
RCE vulnerability reported due to typo in Firefox code
Recent
Patch released for the vulnerability
More articles in this cluster
Continue Reading
Critical Vulnerabilities in Firefox and Thunderbird Require Immediate Patching
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
LongNosedGoblin and UAT-8302: New China-Aligned APT Threats Targeting Governments
PATCHCORD Malware Targets Afghan Telecom and South Asian Infrastructure
Emergency Release of Tails 7.6.2 to Address Critical Tor Browser Vulnerability
Vitalik Buterin Advocates AI Formal Verification to Secure Crypto Networks