Sandbox Escape Vulnerability in Firefox by Mozilla
CVE-2026-100818

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100818?

The vulnerability stems from a use-after-free condition in the Widget: Gtk component, which allows attackers to escape the sandbox and potentially execute arbitrary code within affected Firefox versions. The flaw has been addressed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17. Users are encouraged to upgrade their browser to the latest version to safeguard against potential exploitation.

Affected Version(s)

Firefox 140.17

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.