Same-Origin Policy Bypass in Firefox from Mozilla
CVE-2026-100809

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100809?

A serious vulnerability exists in the DevTools component of Firefox, allowing attackers to bypass the same-origin policy. This could result in unauthorized access to sensitive data, enabling potential exploitation of the affected system. The vulnerability has been addressed in versions Firefox ESR 153.4 and Firefox 157, emphasizing the importance of updating to the latest releases to mitigate security risks. Users are urged to remain vigilant and apply necessary updates promptly.

Affected Version(s)

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Finn Westendorf
.