Sandbox Escape Vulnerability in Mozilla Firefox
CVE-2026-100804

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100804?

A vulnerability identified in the Preferences: Backend component of Mozilla Firefox enables a sandbox escape due to a use-after-free flaw. This could potentially allow an attacker to gain unauthorized access to system resources. The vulnerability has been addressed in Firefox version 157, emphasizing the importance of keeping software updated to mitigate security risks.

Affected Version(s)

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.