What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Mozilla fixed CVE-2019-17026 in January 2020 after confirming that attackers were exploiting the critical Firefox flaw in targeted attacks. The patch was Firefox 72.0.1 or Firefox ESR 68.4.1 at the time; both versions are obsolete, so they are not suitable update targets today.
What was the Firefox zero-day?
CVE-2019-17026 was a critical vulnerability in IonMonkey, the just-in-time JavaScript compiler in Firefox’s SpiderMonkey engine. Mozilla described it as: “Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.”
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Mozilla Firefox '22: 2. Auflage (German Edition) | $6.99 | Buy on Amazon |
| 2 |
|
Mozilla Firefox: Introductory Concepts And Techniques | $94.01 | Buy on Amazon |
| 3 |
|
Learning Firefox OS Application Development | $34.99 | Buy on Amazon |
A type confusion occurs when software handles a value as though it has a different type than it actually does. Mozilla’s advisory identifies this flaw and its potential consequence, but does not provide further technical details about how the attacks worked.
Did attackers exploit it in the wild?
Yes. In its January 8, 2020 security advisory, Mozilla said: “We are aware of targeted attacks in the wild abusing this flaw.” Mozilla rated the issue critical and credited Qihoo 360 ATA as the reporter. The advisory does not name an attacker, victims, campaign objective, malware, or confirmed impact.
#1 Best Overall
SecurityWeek reported the incident on January 9, 2020, and noted that Mozilla had not provided additional details about the attacks: SecurityWeek’s report.
Which Firefox versions fixed CVE-2019-17026?
Mozilla’s January 2020 advisory named these fixed releases:
Rank #2
- Used Book in Good Condition
| Product | Historical fixed version |
|---|---|
| Firefox | 72.0.1 |
| Firefox ESR | 68.4.1 |
These version numbers are historical, not current recommendations. Mozilla’s advisory gives the date, severity, affected component, reporter, and remediation versions: Mozilla Foundation Security Advisory 2020-03.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What should Firefox users do now?
Use a supported Firefox release delivered through Mozilla’s update channel. The 2020 fixed releases are obsolete, and the sources cited here do not establish the current Firefox version number. Do not install an old 2020 build as a substitute for updating to a supported release.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

