Off-by-one in Mozilla products - CVE-2026-100794
Published: September 29, 2026
Vulnerability identifier: #VU152837
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-100794
CWE-ID: CWE-193
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escape the browser sandbox.
The vulnerability exists due to incorrect boundary conditions in the Internationalization component when processing content. A remote attacker can trigger the incorrect boundary condition to escape the browser sandbox.
Affected software
Firefox ESR
Mozilla Firefox
Firefox for Android
Mozilla Firefox
Firefox for Android
How to mitigate CVE-2026-100794
Install security update from vendor's website.
Firefox ESR - addressed in versions 140.17.0, 153.4.0
Firefox for Android - update to 157.0
Mozilla Firefox - update to 157.0
Firefox for Android - update to 157.0
Mozilla Firefox - update to 157.0