Privilege Escalation in Firefox and Firefox ESR by Mozilla
CVE-2026-100807

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100807?

A privilege escalation vulnerability has been identified in the Service Workers component of Firefox, allowing unauthorized access to certain functionalities. This flaw, if exploited, could enable an attacker to elevate their privileges and gain access to restricted areas of the application. Mozilla has addressed this issue in designated versions of Firefox and Firefox ESR, ensuring users can maintain secure browsing experiences. It is vital for users to update to the latest versions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Firefox 140.17

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khanh Nguyen
.