An error in the ECMA-262 specification relating to Async Generators could have resulted in a type confusion, potentially leading to memory corruption and an exploitable crash. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
No PoCs from references.
- https://github.com/5211-yx/javascript_fuzzer
- https://github.com/googleprojectzero/fuzzilli