Mitigation Bypass in Firefox Browser's Bookmarks and History Component
CVE-2026-100828

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-100828?

A technical flaw in Firefox's Bookmarks & History component allows attackers to bypass specific security mitigations. This vulnerability affects users of Firefox versions ESR 153.4 and 157. By exploiting this issue, malicious actors could potentially manipulate browser behavior in unforeseen ways. Users are encouraged to update their browsers to the latest versions to ensure their systems remain secure, as Mozilla has addressed this issue in subsequent updates.

Affected Version(s)

Firefox 153.4

Firefox 157

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rintaro Kawasugi
.