Invalid Pointer Vulnerability in Firefox and Firefox ESR
CVE-2026-100788

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100788?

This vulnerability in the WebAssembly component of Firefox and Firefox ESR arises from the handling of invalid pointers, potentially leading to unexpected behavior or exploitation. It has been addressed in recent updates, specifically Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17, ensuring enhanced security and stability for users.

Affected Version(s)

Firefox 140.17

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.