Description
Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

Uninitialized memory in the Storage: Quota Manager component can allow an attacker to read data that was not intended for that process, potentially revealing sensitive information or causing unpredictable behaviour. The weakness corresponds to improper initialization of variables, identified as CWE-665.

Affected Systems

Mozilla:Firefox is affected. The vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. All earlier builds that have not applied these patches are at risk.

Risk and Exploitability

The CVSS score is not published, and the EPSS score is not available, so precise severity and likelihood are unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The likely attack vector is local; any code that triggers quota management in the browser can read uninitialized memory, so a malicious website or local process could exploit it. Given the lack of public exploits and high complexity of inducing the exact memory state, the risk is considered moderate until the patch is applied.

Generated by OpenCVE AI on September 29, 2026 at 16:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to a fixed version – ESR 153.4 or newer, or release 157, ESR 115.42, or ESR 140.17.
  • If an update is not immediately possible, restrict or disable the quota manager feature in the browser configuration to reduce the window of vulnerability.
  • Continuously monitor browser telemetry or logs for abnormal storage or memory usage patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 29, 2026 at 16:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Uninitialized memory in the Storage: Quota Manager component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Uninitialized memory in the Storage: Quota Manager component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:35:54.685Z

Reserved: 2026-09-26T19:15:16.495Z

Link: CVE-2026-100759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.213

Modified: 2026-09-29T13:17:40.213

Link: CVE-2026-100759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:45:17Z

Weaknesses