In Firefox 149.0, the vulnerability I reported was assigned CVE-2026-4696(Use After Free in the Layout:Text and Fonts component)
I have wanted to earn a CVE in Firefox for a long time, so I am very happy about this.
I played DEF CON CTF Quals as part of Blue Water, mainly looking at the web+pwn challenges.
I couldn’t solve them in the end, which is frustrating because I felt like I had a rough idea of what needed to be done.