Description
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Sandbox Escape (privilege escalation).
Action: Immediate Patch
AI Analysis

Impact

Firefox contains a use‑after‑free bug in the DOM that allows an attacker to escape the sandbox used by content processes. If triggered, the vulnerability can lead to arbitrary code execution or escalation of privileges within the browser context. The flaw arises from improper memory deallocation and subsequent reuse, which is reflected in the CWE-416 classification.

Affected Systems

The vulnerability is present in Mozilla Firefox releases prior to ESR 153.4, Firefox 157, ESR 115.42, and ESR 140.17. Users running these affected builds, or older ESR releases, are exposed, while any edition that includes one of the listed fix versions provides protection.

Risk and Exploitability

The CVSS score is not provided, and the EPSS value is unavailable. The vulnerability is not listed in the CISA KEV catalog, so no active exploitation campaigns are publicly known. Nonetheless, sandbox escape represents a high‑impact flaw that could be leveraged wherever an adversary can supply or influence DOM content. Attackers would need to trigger the use‑after‑free, possibly via crafted web content, but details on the exact attack vector are not supplied in the data.

Generated by OpenCVE AI on September 29, 2026 at 16:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox 157 or later, or to any newer ESR release that includes the fix (e.g., ESR 115.42, 140.17, or 153.4).
  • If an update cannot be applied immediately, restrict the loading of untrusted content by disabling third‑party plugins or using content filtering to block scripts that may trigger the bug.
  • Continuously monitor Mozilla security advisories and deploy subsequent patches as soon as they are released.

Generated by OpenCVE AI on September 29, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Sandbox escape due to use-after-free in the DOM: Content Processes component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:40:06.477Z

Reserved: 2026-09-26T19:15:19.245Z

Link: CVE-2026-100762

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:40.470

Modified: 2026-09-29T13:17:40.470

Link: CVE-2026-100762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:15:14Z

Weaknesses

No weakness.