One of the two men who publicly disclosed a Mozilla Firefox JavaScript vulnerability over the weekend at a hacker conference now claims the bug does not allow for remote code execution.