AI description
**CVE-2026-100828** is a security vulnerability affecting the Bookmarks & History component of Mozilla Firefox and Thunderbird. Reported by researcher Rintaro Kawasugi, the flaw allows for a mitigation bypass within this specific component. While the underlying technical mechanisms and exact downstream consequences of the bypass are not detailed in public advisories, the vulnerability enables an attacker to circumvent established security mitigations. The issue affects versions of Firefox prior to 157, Firefox ESR prior to 153.4, and Thunderbird prior to versions 157 and 153.4. Mozilla addressed the vulnerability in late September 2026, releasing patches in Firefox 157, Firefox ESR 153.4, and Thunderbird 153.4 and 157. Users are encouraged to update their software to these versions or later to resolve the issue.
- Description
- Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
- Source
- security@mozilla.org
- NVD status
- Undergoing Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.6
- Impact score
- 6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-693
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4