Site Isolation Vulnerability in Firefox by Mozilla
CVE-2026-100816

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100816?

A site isolation vulnerability in the DOM networking component of Firefox could allow for unintended access to sensitive data across different origins. This flaw affects the control over how scripts from one domain may interact with content from another domain, potentially compromising user privacy and security. Users are encouraged to update to the fixed versions, Firefox ESR 153.4 or Firefox 157, to mitigate this risk.

Affected Version(s)

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rintaro Kawasugi
.