Skip to content
feed: live
>_0dayNews
mozilla

Firefox 157 Patches Two CVSS 9.6 Sandbox Escapes

Mozilla patched five vulnerabilities in Firefox 157, including two CVSS 9.6 sandbox escapes via use-after-free in the DOM Content Processes component.

Firefox 157 Patches Two CVSS 9.6 Sandbox Escapes
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
loopNadia "Loop" Park·Published ·2 min read

Firefox is still running in most enterprise desktop fleets. As of September 29, any installation older than Firefox 157 carries two use-after-free flaws in the DOM Content Processes component, both scored CVSS 9.6 and capable of enabling sandbox escape from the renderer process.

What the renderer process is and why it matters here

The DOM Content Processes component is Firefox’s sandboxed renderer: it handles untrusted web content in a process explicitly isolated from the main browser process and from OS resources the browser itself can access. That isolation is the layer standing between a malicious web page and the rest of a workstation. A use-after-free in that component gives an attacker code execution inside the sandbox. Chained with a follow-on step, that execution exits the sandbox boundary entirely.

CVE-2026-100770 and CVE-2026-100762 are both that kind of flaw: use-after-free in the renderer, CVSS 9.6, fixed across four release lines. The version inventory matters for fleet management:

  • Firefox 157: fixes all five vulnerabilities in this release, including the three WebGPU flaws below.
  • Firefox ESR 153.4: fixes CVE-2026-100770, CVE-2026-100762, plus the three WebGPU flaws.
  • Firefox ESR 140.17 and ESR 115.42: fix CVE-2026-100770 and CVE-2026-100762 only. The WebGPU flaws are not patched on these tracks.

If your fleet is pinned to ESR 115 or ESR 140 for compatibility reasons, patching to the latest point release addresses the two critical flaws. The WebGPU surface stays unpatched on those tracks, which matters for environments where desktop users can access GPU-accelerated web content.

The three WebGPU flaws

Three additional vulnerabilities in Firefox’s WebGPU implementation are patched in Firefox 157 and ESR 153.4:

  • CVE-2026-100768 (CVSS 8.8, High): Use-after-free in Graphics: WebGPU.
  • CVE-2026-100764 (CVSS 8.8, High): Privilege escalation from incorrect boundary conditions in Graphics: WebGPU.
  • CVE-2026-100761 (CVSS 8.8, High): Privilege escalation from use-after-free in Graphics: WebGPU.

WebGPU runs inside the renderer process. A flaw there can function as a second step: code execution in the renderer via a DOM flaw, then privilege escalation via a WebGPU flaw into a higher-privilege context within the browser process.

Exploitation status

Mozilla has not reported active exploitation of any of these five vulnerabilities. No public proof-of-concept code is known at the time of publication.

Patching priority for fleet administrators

The practical question for an enterprise browser deployment is which ESR track you’re on. ESR 115 and ESR 140 have the smallest footprint for the two critical fixes but leave the WebGPU surface unpatched. ESR 153.4 closes all five. Firefox 157 closes all five and is the current stable release. For environments where desktop users regularly visit arbitrary web content, updating to ESR 153.4 or Firefox 157 closes every surface addressed in this release.


Related coverage: Firefox JIT Flaw Enables Tor Browser Code Execution | Firefox exploit code public; Chrome, Adobe patch same day | BlueMoon Exploit Kit Chains Chrome, Windows Zero-Days

Found this useful? Share it.