Description
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Sandbox escape allowing arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free bug in Firefox’s DOM Content Processes component enables an attacker to escape the browser’s sandbox. The flaw arises when an object is freed while still in use, allowing malformed or malicious input to corrupt memory. If exploited, it can provide an attacker with the ability to execute arbitrary code outside the isolation boundaries normally imposed by the browser, potentially compromising the entire host system.

Affected Systems

This vulnerability affects all Mozilla Firefox releases older than Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Any installation running a build prior to those patched versions is susceptible.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating that no widespread exploitation has been reported yet. However, the nature of a use‑after‑free leading to sandbox escape suggests a high potential impact. The likely attack vector is through crafted web content or malicious extensions that can trigger the error in a content process. Given the severity implied by the description, rapid patching is recommended to mitigate possible exploitation.

Generated by OpenCVE AI on September 29, 2026 at 17:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to at least version 157 or the corresponding ESR release that includes the fix (ESR 153.4, ESR 115.42, or ESR 140.17).
  • Ensure that the browser’s sandboxing feature remains enabled and that privileged content processes are used only with trusted content.
  • Remove or update any extensions that rely on privileged content processes, such as certain ad‑blockers or theme add‑ons, until the vulnerability is patched.

Generated by OpenCVE AI on September 29, 2026 at 17:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Sandbox escape due to use-after-free in the DOM: Content Processes component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:40:06.326Z

Reserved: 2026-09-26T19:15:26.594Z

Link: CVE-2026-100770

cve-icon Vulnrichment

Updated: 2026-09-29T16:30:00.960Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:41.250

Modified: 2026-09-29T17:17:03.517

Link: CVE-2026-100770

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T17:30:17Z

Weaknesses