AI description
CVE-2026-100829 is a security vulnerability identified in the DOM: Security component of several Mozilla products, including Firefox, Firefox ESR, and Thunderbird. Reported by researcher Rintaro Kawasugi, the flaw stems from improper security control enforcement within the DOM security component. This issue allows a remote attacker to interact with the affected component and bypass built-in security mitigation mechanisms. Mozilla has addressed this vulnerability in its security advisories MFSA2026-97 and MFSA2026-100. The issue is resolved in Firefox 157, Firefox ESR 153.4, Thunderbird 157, and Thunderbird 153.4. To prevent potential exploitation, users are advised to update their installations to these patched versions, though there are currently no reports of active exploits in the wild.
- Description
- Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 153.4, and Firefox 157.
- Source
- security@mozilla.org
- NVD status
- Undergoing Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.6
- Impact score
- 6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-693
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4