Description
Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Firefox's graphics component that allows an attacker to escape the browser sandbox and execute arbitrary code outside the sandbox. This memory corruption bug can be triggered by specially crafted media or web content, potentially compromising the integrity of the host system.

Affected Systems

Mozilla Firefox is affected. The remedial releases that contain the fix are Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. Any user running a version prior to these patched releases remains vulnerable.

Risk and Exploitability

No CVSS score is provided and the EPSS is reported as unavailable, indicating that public exploitation data is sparse. The vulnerability is not listed in the CISA KEV catalog. Although the flaw provides high‑impact capabilities, the lack of observable active exploits suggests a low‑to‑moderate likelihood of exploitation under normal conditions. The attack vector is inferred to be remote, as the bug is triggered by content processed by the graphics engine.

Generated by OpenCVE AI on September 29, 2026 at 16:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to a patched version—ESR 153.4, ESR 140.17, ESR 115.42, or the latest Firefox 157 release.
  • If an immediate upgrade is not possible, disable or restrict the use of graphics APIs that invoke the vulnerable component, such as disabling canvas or media playback.
  • Stay alert for additional advisory releases from Mozilla and apply subsequent patches as they become available.

Generated by OpenCVE AI on September 29, 2026 at 16:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the Graphics component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Sandbox escape due to use-after-free in the Graphics component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T16:28:14.639Z

Reserved: 2026-09-26T19:17:08.056Z

Link: CVE-2026-100786

cve-icon Vulnrichment

Updated: 2026-09-29T16:28:05.380Z

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:43.583

Modified: 2026-09-29T17:17:04.003

Link: CVE-2026-100786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:45:17Z

Weaknesses