Sandbox Escape Vulnerability in Firefox by Mozilla
CVE-2026-100794

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100794?

A vulnerability has been identified in the internationalization component of Firefox, where incorrect boundary conditions can allow for a potential sandbox escape. This issue has been addressed in the updates for Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. Users are advised to update to the latest versions to mitigate the risk associated with this flaw.

Affected Version(s)

Firefox 140.17

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.