Sandbox Escape Vulnerability in Firefox by Mozilla
CVE-2026-100811

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100811?

A sandbox escape vulnerability has been identified due to a use-after-free error in the DOM components of Mozilla Firefox. This flaw could potentially allow an attacker to manipulate the document object model, leading to unauthorized actions within a restricted environment. Updates to address this vulnerability have been released in specific versions, including Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17, highlighting the importance of keeping browsers up to date to mitigate security risks.

Affected Version(s)

Firefox 140.17

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yaqoub Aldurayhim
.