Description
Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Sandbox escape leading to potential code execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Graphics component lets a malicious payload escape Firefox's sandbox, potentially allowing code to run with higher privileges than intended. The vulnerability is a classic privilege‑escalation issue that can compromise system integrity when exploited. It is a direct result of improper access control within the rendering engine, enabling the attacker to break containment.

Affected Systems

Mozilla Firefox is affected. The original article notes fixes in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17; earlier releases lack the patch. Exact vulnerable versions are not enumerated in the advisory, but any build older than those mentioned is likely at risk.

Risk and Exploitability

No EPSS score is provided, and the vulnerability is not currently listed in the CISA KEV catalog; nevertheless the inherent capabilities of a sandbox escape suggest a high impact. No publicly known exploits have been reported, but the attack vector is inferred to be content delivered via a web page or plugin that triggers the graphics subsystem, so web‑based attacks are the likely scenario.

Generated by OpenCVE AI on September 29, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox ESR 153.4, Firefox 157, or any newer ESR version such as 115.42 or 140.17 that includes the fix
  • Audit and test the environment to confirm that no older, unpatched Firefox binaries remain in use
  • Stay informed by checking Mozilla security advisories until a later, more comprehensive patch is released

Generated by OpenCVE AI on September 29, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-264
CWE-285

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Sandbox escape in the Graphics component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:03.907Z

Reserved: 2026-09-26T19:15:31.053Z

Link: CVE-2026-100775

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T13:17:42.083

Modified: 2026-09-29T21:27:41.130

Link: CVE-2026-100775

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:30:17Z

Weaknesses