All findings

CVE-2026-8390 high

GPT-5.5 safety evaluation surfaces high-severity Firefox WebAssembly UAF

Mozilla credits OpenAI Preparedness and Bill Demirkapi on a high-impact Firefox WebAssembly use-after-free; OpenAI says GPT-5.5 found it during safety evaluation.

Bug class
Use-after-free in browser JavaScript engine
Affected codebase
Mozilla Firefox WebAssembly
Credited system
OpenAI Daybreak
Disclosed
June 22, 2026
Attribution
Direct source attribution
Severity
high
Source status: Mozilla directly credits OpenAI Preparedness and Bill Demirkapi and assigns High impact. OpenAI's primary disclosure identifies GPT-5.5 as the discovery model.

Summary

CVE-2026-8390 is a use-after-free in Firefox’s WebAssembly implementation. Mozilla rated it High and fixed it in Firefox 150.0.3. OpenAI says GPT-5.5 identified the issue during a model safety evaluation and that it was patched shortly before Pwn2Own Berlin.

Attribution

The evidence chain is direct on both sides: Mozilla names the OpenAI reporters, and OpenAI names the model and evaluation context.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.