Privilege Escalation Vulnerability in Firefox by Mozilla
CVE-2026-100801

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100801?

A privilege escalation vulnerability exists in the DLL Services component of Firefox, potentially allowing an attacker to gain elevated access to system resources. This issue affects specific versions of Firefox and Firefox ESR, highlighting the need for users to update to the latest versions to mitigate the risks associated with unauthorized access. Mozilla has released fixes for these vulnerabilities in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17, urging users to apply these updates promptly.

Affected Version(s)

Firefox 140.17

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.