Same-Origin Policy Bypass in Firefox WebExtensions by Mozilla
CVE-2026-100803

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100803?

A vulnerability in the WebExtensions component of Mozilla Firefox has been identified, allowing attackers to bypass the same-origin policy. This issue can potentially lead to unauthorized access to sensitive data across different origins. Mozilla has addressed this vulnerability in multiple versions, including Firefox ESR 153.4, Firefox 157, and several others. Users are advised to update their browsers to maintain security and protect against possible exploits.

Affected Version(s)

Firefox 115.42

Firefox 140.17

Firefox 153.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqoub Aldurayhim
.