Description
Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Published: 2026-09-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure via site isolation bypass
Action: Apply Patch
AI Analysis

Impact

A flaw in the Panning and Zooming component of Firefox allows a web page to bypass the browser’s site isolation protections, potentially exposing data or code belonging to other web origins. This weakness can lead to unintended data leakage or cross‑origin instrumentation, but it does not grant direct code execution. The underlying deficiency is a failure to maintain proper isolation boundaries within the rendering engine.

Affected Systems

Mozilla Firefox users running versions prior to Firefox 157, or ESR releases older than ESR 153.4, ESR 115.42 or ESR 140.17, are vulnerable. The issue is fixed in those releases and later versions; updating to any of those builds removes the flaw.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is unknown. No active exploits have been reported, but a malicious site could trigger the bug by manipulating page panning or zooming, exploiting the bypass of site isolation. Given the potential for sensitive data exposure and the lack of readily known mitigations, the vulnerability should be treated as high risk until a confirmed patch or workaround is deployed.

Generated by OpenCVE AI on September 30, 2026 at 07:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Firefox to 157 or later, or to the latest ESR version (ESR 153.4, ESR 115.42, or ESR 140.17) to include the patch.
  • If an upgrade cannot be performed immediately, defer use of sites that rely heavily on pan or zoom features until a future release, and apply organizational controls to limit execution of untrusted content that might trigger the component.
  • Continuously monitor Mozilla security advisories and apply any subsequent patches or mitigations as they become available.

Generated by OpenCVE AI on September 30, 2026 at 07:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 29 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Panning and Zooming component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Title Site isolation issue in the Panning and Zooming component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-09-29T12:36:30.318Z

Reserved: 2026-09-26T19:18:35.743Z

Link: CVE-2026-100821

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T13:17:47.400

Modified: 2026-09-29T21:27:41.130

Link: CVE-2026-100821

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:45:18Z

Weaknesses

No weakness.