Mozilla Foundation Security Advisory 2026-98
Security Vulnerabilities fixed in Firefox ESR 115.42
- Announced
- September 29, 2026
- Impact
- high
- Products
- Firefox ESR
- Fixed in
-
- Firefox ESR 115.42
Note: We have changed how we publish advisories. We no longer roll all internally identified memory safety vulnerabilities into a single CVE and are now issuing an advisory for every individual bug.
#CVE-2026-100756: Incorrect boundary conditions in the Audio/Video: Playback component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100757: Use-after-free in the Widget component
- Reporter
- Mohamed Mbarek
- Impact
- high
References
#CVE-2026-100758: Sandbox escape in the DOM: Navigation component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100759: Uninitialized memory in the Storage: Quota Manager component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100762: Sandbox escape due to use-after-free in the DOM: Content Processes component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100766: Information disclosure in the Networking: JAR component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100767: Use-after-free in the Networking: Cache component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100770: Sandbox escape due to use-after-free in the DOM: Content Processes component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100771: Undefined behavior in the DOM: Streams component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100773: Use-after-free in the Storage: IndexedDB component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100774: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100775: Sandbox escape in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100777: Use-after-free in the Graphics: Canvas2D component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100778: Sandbox escape due to use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100779: Use-after-free in the XSLT component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100780: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100781: Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100782: Privilege escalation due to incorrect boundary conditions in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100783: Uninitialized memory in the Audio/Video component
- Reporter
- 5up3rh3i
- Impact
- high
References
#CVE-2026-100784: Use-after-free in the Layout: Text and Fonts component
- Reporter
- 5up3rh3i
- Impact
- high
References
#CVE-2026-100785: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100786: Sandbox escape due to use-after-free in the Graphics component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100789: Use-after-free in the Graphics: Canvas2D component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100790: Use-after-free in the XSLT component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100791: Use-after-free in the DOM: Core & HTML component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100832: Use-after-free in the Graphics: Canvas2D component
- Reporter
- Mozilla
- Impact
- high
References
#CVE-2026-100797: Privilege escalation due to use-after-free in the Graphics: WebRender component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-100803: Same-origin policy bypass in the WebExtensions component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-100819: Sandbox escape due to incorrect boundary conditions in the XPCOM component
- Reporter
- Mozilla
- Impact
- moderate
References
#CVE-2026-100821: Site isolation issue in the Panning and Zooming component
- Reporter
- Nguyen Thanh Nguyen
- Impact
- moderate