Site Isolation Vulnerability in Firefox Browser by Mozilla
CVE-2026-100821

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100821?

A site isolation vulnerability in the Panning and Zooming component of Mozilla's Firefox browser could potentially allow attackers to bypass security measures and access sensitive data across different sites. This issue was identified and subsequently resolved in Firefox versions 153.4, 157, 115.42, and 140.17. Users are advised to update to the latest versions to ensure complete protection against potential exploitation of this issue.

Affected Version(s)

Firefox 115.42

Firefox 140.17

Firefox 153.4

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Thanh Nguyen
.