XPCOM Component Sandbox Escape in Firefox by Mozilla
CVE-2026-100819

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100819?

The vulnerability arises from incorrect boundary conditions in the XPCOM component, which allows attackers to execute code outside the intended sandbox environment. This flaw can be exploited to bypass security mechanisms designed to isolate processes, leading to potential unauthorized access to the system. Mozilla has addressed this issue in several updates, including Firefox ESR versions 153.4 and 115.42, and standard versions 157 to ensure better security.

Affected Version(s)

Firefox 115.42

Firefox 140.17

Firefox 153.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mozilla
.