Description
Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Same‑origin policy bypass via DevTools
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the Firefox DevTools component allows an attacker to bypass the browser’s same‑origin policy, potentially exposing cross‑origin data or executing code across site boundaries. The flaw permits unauthorized access to resources that should be protected by the same‑origin restrictions, which could lead to data leakage, session hijacking, or execution of malicious content in a trusted context. The vulnerability is a direct result of improper authorization handling within the DevTools subsystem.

Affected Systems

Mozilla Firefox is affected, with the fix applied in Firefox ESR 153.4 and Firefox 157. Versions prior to these releases are potentially vulnerable. No specific lower bound is listed, so any build before the mentioned versions should be considered at risk.

Risk and Exploitability

No CVSS score is provided in the data, and the EPSS score is not available, making it difficult to quantify exact risk quantitatively. The CVE is not listed in the CISA KEV catalog, indicating no known public exploits at the time of the advisory. The likely attack vector is local: a user or local script that can access DevTools may exploit the flaw to read or modify cross‑origin information. The bypass could be used to exfiltrate data or inject malicious payloads if the attacker can drive user interaction with the DevTools interface. Given the nature of a same‑origin policy failure, the potential impact could be high if an attacker can co‑ordinate the exploit with compromised content or phishing pages.

Generated by OpenCVE AI on September 30, 2026 at 02:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the security update to Firefox ESR 153.4 or Firefox 157, which includes the fix for the same‑origin policy bypass in DevTools.
  • If an upgrade cannot be performed immediately, disable or restrict use of DevTools by setting the preference "devtools.toolbox.disabled" to true in about:config or via an enterprise policy.
  • Monitor browser logs for unusual cross‑origin requests originating from DevTools and investigate any anomalies.

Generated by OpenCVE AI on September 30, 2026 at 02:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the DevTools component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Title Same-origin policy bypass in the DevTools component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:23.516Z

Reserved: 2026-09-26T19:18:06.677Z

Link: CVE-2026-100809

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T13:17:46.023

Modified: 2026-09-29T21:27:41.130

Link: CVE-2026-100809

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T02:15:07Z

Weaknesses