Single-Character Typo Causes 0-Day RCE Vulnerability in Firefox

Single-Character Typo Causes 0-Day RCE Vulnerability in Firefox

First seen 18 Feb 2026, 20:21 UTC CybersecuritynewsXLinkedin 64.2

Article Content

Browse articles
ThreatCluster

A critical Remote Code Execution (RCE) vulnerability in Mozilla Firefox was identified due to a single-character typo in the SpiderMonkey JavaScript engine’s WebAssembly garbage collection code. The error occurred when a developer mistakenly typed '&' instead of '|', leading to the flaw's discovery by security researcher Erge while reviewing the Firefox 149 Nightly source code.

Timeline

2026-02-18
RCE vulnerability reported due to typo in Firefox code
Recent
Patch released for the vulnerability