VYPR
patchPublished Sep 29, 2026· Updated Oct 1, 2026· 1 source

Firefox ESR: 25 Coordinated Vulnerability Disclosures Include Critical Sandbox Escapes

Key findings • 25 vulnerabilities disclosed for Firefox ESR, Thunderbird, and Firefox on September 29, 2026. • Critical sandbox escape flaws (CVE-2026-100819, CVE-2026-100818) and high-severi…

Key findings

  • 25 vulnerabilities disclosed for Firefox ESR, Thunderbird, and Firefox on September 29, 2026.
  • Critical sandbox escape flaws (CVE-2026-100819, CVE-2026-100818) and high-severity use-after-free bugs reported.
  • Vulnerabilities impact memory corruption, privilege escalation, information disclosure, and sandbox escapes.
  • All issues fixed in Firefox ESR 153.4 and corresponding Thunderbird/Firefox versions.
  • Users are urged to update to Firefox ESR 153.4 immediately.

On September 29, 2026, Mozilla disclosed a significant batch of 25 vulnerabilities affecting Firefox ESR, Thunderbird, and Firefox. The vulnerabilities, disclosed simultaneously, span a range of severities, including critical sandbox escapes and high-severity use-after-free bugs. This coordinated disclosure impacts multiple components within the affected Mozilla products, highlighting the interconnectedness of their codebases.

Several vulnerabilities fall into the "use-after-free" category, a common memory corruption flaw. These include CVE-2026-100832 and CVE-2026-100815 in the Graphics: Canvas2D and CSS Parsing and Computation components, respectively. Additionally, CVE-2026-100825 in the JavaScript Engine: JIT and CVE-2026-100814 also in the JavaScript Engine: JIT component, represent critical areas of concern.

A particularly alarming set of vulnerabilities are the sandbox escapes, with CVE-2026-100819 in the DOM: Core & HTML component and CVE-2026-100818 in the Widget: Gtk component both rated critical with a CVSSv3 score of 9.6. These flaws could allow attackers to break out of the browser's security sandbox, potentially leading to broader system compromise. Privilege escalation is another significant theme, with CVE-2026-100824 in the Places component, CVE-2026-100820 in the Address Bar, CVE-2026-100807 in the DOM: Service Workers component, and CVE-2026-100801 in the DLL Services component all carrying high severity ratings.

Other notable vulnerabilities include information disclosure in the Networking component (CVE-2026-96869), mitigation bypasses in DOM components (CVE-2026-100829, CVE-2026-100830, CVE-2026-100828, CVE-2026-100808), and denial-of-service vulnerabilities in the Storage: StorageManager (CVE-2026-100826) and Graphics (CVE-2026-100812) components. Spoofing issues in the Networking: HTTP component (CVE-2026-100822) and site isolation issues in Panning and Zooming (CVE-2026-100821) and DOM: Networking (CVE-2026-100815) were also part of this disclosure.

All 25 vulnerabilities were fixed in Firefox ESR 153.4. Other affected products like Thunderbird and Firefox also received patches in their respective versions, including Thunderbird 157, 140.17, 153.4, and Firefox 157, 115.42, 140.17. Users of Firefox ESR are strongly urged to update to version 153.4 to mitigate these risks.

This large, coordinated disclosure underscores the importance of timely patching for all Mozilla products. The presence of critical sandbox escapes and multiple privilege escalation vulnerabilities highlights the potential impact if these issues are exploited. Users should prioritize updating their installations to the latest versions to protect against these security threats.

The related news coverage from Vypr Intelligence confirms the critical nature of these vulnerabilities, specifically mentioning the sandbox escapes and use-after-free bugs, and urging users to update. The report also notes that vulnerabilities impact memory corruption, privilege escalation, and information disclosure.

The batch of vulnerabilities includes: CVE-2026-96869, CVE-2026-100832, CVE-2026-100831, CVE-2026-100830, CVE-2026-100829, CVE-2026-100828, CVE-2026-100826, CVE-2026-100825, CVE-2026-100824, CVE-2026-100822, CVE-2026-100821, CVE-2026-100820, CVE-2026-100819, CVE-2026-100818, CVE-2026-100816, CVE-2026-100815, CVE-2026-100814, CVE-2026-100812, CVE-2026-100811, CVE-2026-100809, CVE-2026-100808, CVE-2026-100807, CVE-2026-100806, CVE-2026-100803, CVE-2026-100801.

Synthesized by Vypr AI