SB2026092960 - Multiple vulnerabilities in Mozilla Firefox
Published: September 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 62 vulnerabilities.
1) Resource exhaustion (CVE-ID: CVE-2026-100812)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the Graphics component when the component is used. A remote attacker can interact with the affected component to cause a denial of service.
2) Use-after-free (CVE-ID: CVE-2026-100776)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.
3) Untrusted Pointer Dereference (CVE-ID: CVE-2026-100788)
CWE-ID: CWE-822 - Untrusted Pointer Dereference
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger invalid pointer handling.
The vulnerability exists due to an invalid pointer in the JavaScript: WebAssembly component when processing content. A remote attacker can trigger invalid pointer handling to trigger invalid pointer handling.
4) Incorrect calculation (CVE-ID: CVE-2026-100792)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a JIT miscompilation.
The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when processing content. A remote attacker can trigger JIT compilation to trigger a JIT miscompilation.
5) Off-by-one (CVE-ID: CVE-2026-100794)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to incorrect boundary conditions in the Internationalization component when processing content. A remote attacker can trigger the incorrect boundary condition to escape the browser sandbox.
6) Information disclosure (CVE-ID: CVE-2026-96869)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose information.
The vulnerability exists due to an information disclosure issue in the Networking component when processing content. A remote attacker can trigger the issue to disclose information.
7) Improper privilege management (CVE-ID: CVE-2026-100801)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the DLL Services component when processing content. A remote attacker can trigger the component issue to escalate privileges.
8) Improper privilege management (CVE-ID: CVE-2026-100807)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the DOM: Service Workers component when processing content. A remote attacker can trigger the component issue to escalate privileges.
9) Use-after-free (CVE-ID: CVE-2026-100811)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.
10) Use-after-free (CVE-ID: CVE-2026-100818)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to use-after-free in the Widget: Gtk component when processing content. A remote attacker can cause the component to access freed memory to escape the browser sandbox.
11) Improper privilege management (CVE-ID: CVE-2026-100820)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper privilege management in the Address Bar component when processing content. A remote attacker can trigger the component issue to escalate privileges.
12) Protection mechanism failure (CVE-ID: CVE-2026-100760)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper sandbox enforcement in the Security: Process Sandboxing component when the component is used. A remote attacker can interact with the affected component to escape the sandbox.
13) Protection mechanism failure (CVE-ID: CVE-2026-100787)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper sandbox enforcement in the XUL component when the component is used. A remote attacker can interact with the affected component to escape the sandbox.
14) Use-after-free (CVE-ID: CVE-2026-100800)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when the component is used. A remote attacker can trigger the use-after-free to escape the sandbox.
15) Protection mechanism failure (CVE-ID: CVE-2026-100808)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper security control enforcement in the DOM: Service Workers component when the component is used. A remote attacker can interact with the affected component to bypass a security mitigation.
16) Improper access control (CVE-ID: CVE-2026-100809)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the DevTools component when the component is used. A remote attacker can interact with the affected component to bypass the same-origin policy.
17) Use-after-free (CVE-ID: CVE-2026-100772)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.
18) Improper access control (CVE-ID: CVE-2026-100816)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper isolation enforcement in the DOM: Networking component when the component is used. A remote attacker can interact with the affected component to bypass site isolation.
19) Spoofing attack (CVE-ID: CVE-2026-100822)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof content.
The vulnerability exists due to improper user interface presentation in the Networking: HTTP component when the component is used. A remote attacker can interact with the affected component to spoof content.
20) Improper privilege management (CVE-ID: CVE-2026-100824)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to an unspecified flaw in the Places component when the component is used. A remote attacker can interact with the affected component to escalate privileges.
21) Resource exhaustion (CVE-ID: CVE-2026-100826)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an unspecified flaw in the Storage: StorageManager component when the component is used. A remote attacker can interact with the affected component to cause a denial of service.
22) Protection mechanism failure (CVE-ID: CVE-2026-100828)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper security control enforcement in the Bookmarks & History component when the component is used. A remote attacker can interact with the affected component to bypass a security mitigation.
23) Protection mechanism failure (CVE-ID: CVE-2026-100829)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper security control enforcement in the DOM: Security component when the component is used. A remote attacker can interact with the affected component to bypass a security mitigation.
24) Protection mechanism failure (CVE-ID: CVE-2026-100830)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper security control enforcement in the DOM: Navigation component when the component is used. A remote attacker can interact with the affected component to bypass a security mitigation.
25) Use-after-free (CVE-ID: CVE-2026-100831)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a use-after-free error in the DOM: UI Events & Focus Handling component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.
26) Use-after-free (CVE-ID: CVE-2026-100765)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in the JavaScript: WebAssembly component. A remote attacker can trick the victim into visiting a specially crafted website and execute arbitrary code on the target system.
27) Use-after-free (CVE-ID: CVE-2026-100815)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a use-after-free error in the CSS Parsing and Computation component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.
28) Use-after-free (CVE-ID: CVE-2026-100825)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a use-after-free error in the JavaScript Engine: JIT component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.
29) Buffer overflow (CVE-ID: CVE-2026-100814)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to a boundary error in the JavaScript Engine: JIT. A remote attacker can trigger memory corruption and crash the browser.
30) Use of Uninitialized Variable (CVE-ID: CVE-2026-100806)
CWE-ID: CWE-457 - Use of Uninitialized Variable
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to crash the browser.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component. A remote attacker can trick the victim into visiting a specially crafted website and crash the browser.
31) Cryptographic issues (CVE-ID: CVE-2026-100798)
CWE-ID: CWE-310 - Cryptographic Issues
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to cryptographic issues in Storage: Quota Manager component. A remote attacker can gain access to sensitive information.
32) Off-by-one (CVE-ID: CVE-2026-100781)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebRender component when it is used. A remote attacker can trigger the boundary-condition flaw to escape the sandbox.
33) Use-after-free (CVE-ID: CVE-2026-100757)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Widget component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
34) Protection mechanism failure (CVE-ID: CVE-2026-100758)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper sandbox enforcement in the DOM: Navigation component when it is used. A remote attacker can trigger the sandbox escape to escape the sandbox.
35) Use of uninitialized resource (CVE-ID: CVE-2026-100759)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to uninitialized memory in the Storage: Quota Manager component when it is used. A remote attacker can trigger use of uninitialized memory to execute arbitrary code.
36) Use-after-free (CVE-ID: CVE-2026-100762)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Content Processes component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
37) Information disclosure (CVE-ID: CVE-2026-100766)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper information handling in the Networking: JAR component when it is used. A remote attacker can trigger the information disclosure to disclose sensitive information.
38) Use-after-free (CVE-ID: CVE-2026-100767)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Networking: Cache component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
39) Use-after-free (CVE-ID: CVE-2026-100770)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Content Processes component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
40) Reliance on undefined behavior (CVE-ID: CVE-2026-100771)
CWE-ID: CWE-758 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to undefined behavior in the DOM: Streams component when it is used. A remote attacker can trigger the undefined behavior to execute arbitrary code.
41) Use-after-free (CVE-ID: CVE-2026-100773)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Storage: IndexedDB component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
42) Use-after-free (CVE-ID: CVE-2026-100774)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
43) Protection mechanism failure (CVE-ID: CVE-2026-100775)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper sandbox enforcement in the Graphics component when it is used. A remote attacker can trigger the sandbox escape to escape the sandbox.
44) Use-after-free (CVE-ID: CVE-2026-100777)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
45) Use-after-free (CVE-ID: CVE-2026-100778)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
46) Use-after-free (CVE-ID: CVE-2026-100779)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the XSLT component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
47) Use-after-free (CVE-ID: CVE-2026-100780)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
48) Off-by-one (CVE-ID: CVE-2026-100756)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when it is used. A remote attacker can trigger the boundary-condition flaw to execute arbitrary code.
49) Off-by-one (CVE-ID: CVE-2026-100782)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when it is used. A remote attacker can trigger the boundary-condition flaw to escalate privileges.
50) Use of uninitialized resource (CVE-ID: CVE-2026-100783)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to uninitialized memory in the Audio/Video component when it is used. A remote attacker can trigger use of uninitialized memory to execute arbitrary code.
51) Use-after-free (CVE-ID: CVE-2026-100784)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Layout: Text and Fonts component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
52) Use-after-free (CVE-ID: CVE-2026-100785)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
53) Use-after-free (CVE-ID: CVE-2026-100786)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Graphics component when it is used. A remote attacker can trigger the use-after-free to escape the sandbox.
54) Use-after-free (CVE-ID: CVE-2026-100789)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
55) Use-after-free (CVE-ID: CVE-2026-100790)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the XSLT component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
56) Use-after-free (CVE-ID: CVE-2026-100791)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the DOM: Core & HTML component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
57) Use-after-free (CVE-ID: CVE-2026-100832)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the Graphics: Canvas2D component when it is used. A remote attacker can trigger the use-after-free to execute arbitrary code.
58) Use-after-free (CVE-ID: CVE-2026-100797)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to use-after-free in the Graphics: WebRender component when it is used. A remote attacker can trigger the use-after-free to escalate privileges.
59) Origin validation error (CVE-ID: CVE-2026-100803)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper origin validation in the WebExtensions component when it is used. A remote attacker can trigger the policy bypass to bypass the same-origin policy.
60) Off-by-one (CVE-ID: CVE-2026-100819)
CWE-ID: CWE-193 - Off-by-one Error
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to incorrect boundary conditions in the XPCOM component when it is used. A remote attacker can trigger the boundary-condition flaw to escape the sandbox.
61) Protection mechanism failure (CVE-ID: CVE-2026-100821)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to improper site isolation in the Panning and Zooming component when it is used. A remote attacker can trigger the site-isolation issue to bypass site isolation.
62) Use-after-free (CVE-ID: CVE-2026-100769)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to trigger a use-after-free condition.
The vulnerability exists due to use-after-free in the JavaScript: WebAssembly component when processing content. A remote attacker can cause the component to access freed memory to trigger a use-after-free condition.
Remediation
Install update from vendor's website.
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068335
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-99/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068374
- https://bugzilla.mozilla.org/show_bug.cgi?id=2072413
- https://bugzilla.mozilla.org/show_bug.cgi?id=2073266
- https://bugzilla.mozilla.org/show_bug.cgi?id=2028871
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041248
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057112
- https://bugzilla.mozilla.org/show_bug.cgi?id=2062740
- https://bugzilla.mozilla.org/show_bug.cgi?id=2067973
- https://bugzilla.mozilla.org/show_bug.cgi?id=2069399
- https://bugzilla.mozilla.org/show_bug.cgi?id=2071645
- https://bugzilla.mozilla.org/show_bug.cgi?id=2058017
- https://bugzilla.mozilla.org/show_bug.cgi?id=2071068
- https://bugzilla.mozilla.org/show_bug.cgi?id=2056767
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063488
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063658
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068340
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068648
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051115
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054767
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059222
- https://bugzilla.mozilla.org/show_bug.cgi?id=2066019
- https://bugzilla.mozilla.org/show_bug.cgi?id=2066321
- https://bugzilla.mozilla.org/show_bug.cgi?id=2066770
- https://bugzilla.mozilla.org/show_bug.cgi?id=2067172
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061399
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068404
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057465
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068385
- https://bugzilla.mozilla.org/show_bug.cgi?id=2060408
- https://bugzilla.mozilla.org/show_bug.cgi?id=2055694
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-98/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068434
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049352
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049792
- https://bugzilla.mozilla.org/show_bug.cgi?id=2054736
- https://bugzilla.mozilla.org/show_bug.cgi?id=2059404
- https://bugzilla.mozilla.org/show_bug.cgi?id=2061526
- https://bugzilla.mozilla.org/show_bug.cgi?id=2063680
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068322
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068336
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068346
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068351
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068367
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068375
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068406
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068417
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068422
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047721
- https://bugzilla.mozilla.org/show_bug.cgi?id=2068456
- https://bugzilla.mozilla.org/show_bug.cgi?id=2069804
- https://bugzilla.mozilla.org/show_bug.cgi?id=2070264
- https://bugzilla.mozilla.org/show_bug.cgi?id=2071064
- https://bugzilla.mozilla.org/show_bug.cgi?id=2071067
- https://bugzilla.mozilla.org/show_bug.cgi?id=2072429
- https://bugzilla.mozilla.org/show_bug.cgi?id=2072432
- https://bugzilla.mozilla.org/show_bug.cgi?id=2072433
- https://bugzilla.mozilla.org/show_bug.cgi?id=2072467
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050542
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057988
- https://bugzilla.mozilla.org/show_bug.cgi?id=2071069
- https://bugzilla.mozilla.org/show_bug.cgi?id=2071784
- https://bugzilla.mozilla.org/show_bug.cgi?id=2067190