Description
Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Sandbox Escape
Action: Patch Immediately
AI Analysis

Impact

Sandbox escape in the XUL component allows code executing in a sandboxed process to break out of its confinement and run with elevated privileges. An attacker could exploit this flaw to execute arbitrary code or upgrade privileges, potentially compromising the entire system. The weakness aligns with improper privilege management as the sandbox boundaries are not correctly enforced.

Affected Systems

All Mozilla Firefox releases before ESR 153.4 and all mainline Firefox versions before 157 are affected. The exact version range is not detailed in the advisory, but the vulnerability has been fixed by those releases, implying earlier versions contain the flaw. The issue impacts the XUL component used by Firefox.

Risk and Exploitability

Because the flaw enables sandbox escape, it could be leveraged by malicious web content or compromised extensions to elevate privileges. The attack vector is inferred to be local, triggered by a user visiting a malicious site or running a malicious extension. No EPSS or CVSS scores are available, and the vulnerability is not listed in CISA's KEV catalog, so the exploitation probability is unknown, yet given the potential for complete system compromise, the risk remains high. Administrators should treat this as a high‑priority concern until a patch is applied.

Generated by OpenCVE AI on September 29, 2026 at 16:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox ESR 153.4 or later, or Firefox 157 or later, to apply the vendor fix.
  • If immediate update is not possible, disable the XUL component or restrict privileged web content by updating Firefox's security settings or applying group policy to block XUL loading.
  • Monitor for unusual execution patterns or privilege changes and review system logs for signs of sandbox escape attempts.

Generated by OpenCVE AI on September 29, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-273

Tue, 29 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Sandbox escape in the XUL component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Title Sandbox escape in the XUL component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:10.688Z

Reserved: 2026-09-26T19:17:10.561Z

Link: CVE-2026-100787

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T13:17:43.700

Modified: 2026-09-29T13:17:43.700

Link: CVE-2026-100787

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:45:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-273

    Improper Check for Dropped Privileges