Mozilla developers have added W^X support to Firefox, a security feature intended to protect against basic memory overflow and corruption issues.
W^X (Write XOR Execute) is the name of a security feature introduced in the OpenBSD operating system that Firefox developers have implemented in Firefox's JIT (Just-in-Time) code compiler.
This feature, added by Jan de Mooij, works in Firefox and affects the way code running in the browser interacts with the operating system's memory.

The principle behind the W^X memory protection policy, as described by the OpenBSD implementation, states that a process (a Web page in the case of Firefox) cannot be both writable and executable at the same time.
Starting with the latest Firefox 46 Nightly build, web pages will be able to either write code to memory or execute code in memory, but not at the same time.
By delaying execution time, W^X memory protection prevents certain types of buffer overflow attacks and also ensures that when dynamic arbitrary code is injected into the process's execution stack, Firefox will crash, rather than blindly running potentially malicious code.
Before adding W^X support, Firefox gave web pages full RWX (Read-Write-Execute) permissions. “RWX pages make it easier to exploit certain bugs. "As a result, all modern operating systems store code in executable but non-writable memory and data is usually not executable, see W^X and DEP," said Mr. de Mooij, explaining his decision to add W^X support to Firefox.
What does this mean for regular users? It means that Firefox will toggle special internal functions before switching from a writable to an executable memory state, which will result in some delays.
According to internal tests conducted by Mozilla developers, the performance drop is between 1% and 4%, depending on the benchmark suite. Due to this minimal impact, the team decided to enable R^W memory protection, which is expected to remain enabled by default, unless there are serious bugs and other unforeseen performance issues.
