CVE-2026-100829

Published Sep 29, 2026

Last updated 9 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-100829 is a security vulnerability identified in the DOM: Security component of several Mozilla products, including Firefox, Firefox ESR, and Thunderbird. Reported by researcher Rintaro Kawasugi, the flaw stems from improper security control enforcement within the DOM security component. This issue allows a remote attacker to interact with the affected component and bypass built-in security mitigation mechanisms. Mozilla has addressed this vulnerability in its security advisories MFSA2026-97 and MFSA2026-100. The issue is resolved in Firefox 157, Firefox ESR 153.4, Thunderbird 157, and Thunderbird 153.4. To prevent potential exploitation, users are advised to update their installations to these patched versions, though there are currently no reports of active exploits in the wild.

Description
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
Source
security@mozilla.org
NVD status
Undergoing Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.6
Impact score
6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-693

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4