CVE-2026-100828

Published Sep 29, 2026

Last updated 9 days ago

Overview

AI description

Automated description summarized from trusted sources.

**CVE-2026-100828** is a security vulnerability affecting the Bookmarks & History component of Mozilla Firefox and Thunderbird. Reported by researcher Rintaro Kawasugi, the flaw allows for a mitigation bypass within this specific component. While the underlying technical mechanisms and exact downstream consequences of the bypass are not detailed in public advisories, the vulnerability enables an attacker to circumvent established security mitigations. The issue affects versions of Firefox prior to 157, Firefox ESR prior to 153.4, and Thunderbird prior to versions 157 and 153.4. Mozilla addressed the vulnerability in late September 2026, releasing patches in Firefox 157, Firefox ESR 153.4, and Thunderbird 153.4 and 157. Users are encouraged to update their software to these versions or later to resolve the issue.

Description
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
Source
security@mozilla.org
NVD status
Undergoing Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-693

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4