Description
Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Sandbox escape via use‑after‑free
Action: Immediate update
AI Analysis

Impact

A use‑after‑free flaw in the DOM core and HTML component allows a sandbox escape, letting an attacker run code outside the intended isolation boundaries. This could compromise system integrity, enable privilege escalation, and expose sensitive information. The weakness is directly a use‑after‑free error.

Affected Systems

All Mozilla Firefox releases prior to the following patches are affected: Firefox ESR 115.42, Firefox ESR 140.17, Firefox ESR 153.4, and standard Firefox 157. Any older versions remain vulnerable.

Risk and Exploitability

Detailed CVSS or EPSS data for this issue are not publicly available, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be content delivered by a malicious website or code executed within the browser’s sandbox. An attacker with sufficient access to trigger the use‑after‑free could escape the sandbox and execute arbitrary code on the host system, posing a high damage potential if the sandbox is the only isolation boundary in place.

Generated by OpenCVE AI on September 29, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Mozilla Firefox to version 157 or any ESR release 115.42, 140.17, or 153.4 and apply all pending security patches
  • If unable to update immediately, configure network or content restrictions to limit exposure to untrusted web content
  • Restart the browser after updating to ensure all memory structures are refreshed

Generated by OpenCVE AI on September 29, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Sandbox escape due to use-after-free in the DOM: Core & HTML component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:30:01.298Z

Reserved: 2026-09-26T19:16:48.272Z

Link: CVE-2026-100778

cve-icon Vulnrichment

Updated: 2026-09-29T16:29:58.647Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:42.577

Modified: 2026-09-29T17:17:03.660

Link: CVE-2026-100778

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:30:17Z

Weaknesses