T

Threats

Mozilla Firefox Multiple Critical Vulnerabilities

Overview

Mozilla has published fixes for nine vulnerabilities affecting Firefox and Firefox ESR, including multiple use-after-free flaws and an incorrect boundary condition that could enable sandbox escapes.

Mozilla rates four vulnerabilities as High and five as Moderate, while the supplied project data assigns each a CVSS score of 9.6. Organisations should update to the applicable fixed Firefox or Firefox ESR release.

Vulnerability Breakdown

CVE-2026-100762 - Sandbox escape via use-after-free in DOM Content Processes

  • Severity: Critical, CVSS 9.6. Mozilla impact: High.

  • Description: Mozilla describes a use-after-free in the DOM Content Processes component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.

CVE-2026-100770 - Sandbox escape via use-after-free in DOM Content Processes

  • Severity: Critical, CVSS 9.6. Mozilla impact: High.

  • Description: Mozilla describes a use-after-free in the DOM Content Processes component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.

CVE-2026-100778 - Sandbox escape via use-after-free in DOM Core & HTML

  • Severity: Critical, CVSS 9.6. Mozilla impact: High.

  • Description: Mozilla describes a use-after-free in the DOM Core & HTML component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.

CVE-2026-100786 - Sandbox escape via use-after-free in Graphics

  • Severity: Critical, CVSS 9.6. Mozilla impact: High.

  • Description: Mozilla describes a use-after-free in the Graphics component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, Firefox ESR 115.42. Not affected: Not specified.

CVE-2026-100800 - Sandbox escape via use-after-free in Disability Access APIs

  • Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.

  • Description: Mozilla describes a use-after-free in the Disability Access APIs component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157 and Firefox ESR 153.4. Not affected: Not specified.

CVE-2026-100804 - Sandbox escape via use-after-free in Preferences Backend

  • Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.

  • Description: Mozilla describes a use-after-free in the Preferences Backend component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157. Not affected: Not specified.

CVE-2026-100811 - Sandbox escape via use-after-free in DOM Core & HTML

  • Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.

  • Description: Mozilla describes a use-after-free in the DOM Core & HTML component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, and Firefox ESR 140.17. Not affected: Not specified.

CVE-2026-100818 - Sandbox escape via use-after-free in Widget GTK

  • Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.

  • Description: Mozilla describes a use-after-free in the Widget GTK component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, and Firefox ESR 140.17. Not affected: Not specified.

CVE-2026-100819 - Sandbox escape via incorrect boundary conditions in XPCOM

  • Severity: Critical, CVSS 9.6. Mozilla impact: Moderate.

  • Description: Mozilla describes incorrect boundary conditions in the XPCOM component.

  • Impact: Sandbox escape.

  • Conditions: Not specified in the accessible vendor advisory.

  • Versions: Affected: The vendor has not specified an exact affected-version range as of 29 September 2026. Fixed: Firefox 157, Firefox ESR 153.4, Firefox ESR 140.17, and Firefox ESR 115.42. Not affected: Not specified.

Mitigation

  • Update Firefox and Firefox ESR installations to the applicable fixed release listed above.

  • Confirm the deployed browser channel and version against Mozilla's relevant security advisory before closing remediation.

  • The accessible advisories do not provide a workaround; prioritise the applicable vendor update.

Summary for IT Teams

  • Products: Mozilla Firefox and Firefox ESR

  • Threat Level: Critical, CVSS 9.6. Mozilla advisory impact ratings range from High to Moderate.

  • Action Required: Apply the applicable fixed Mozilla release. Confirm versions across managed endpoints.

Reference

Need Help?

Contact Secure ISS on 1300 769 460 or email the Secure ISS team for assistance assessing exposure and remediation.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.