GHSA-9m3c-9jr3-3cgrHighCVSS 8.1
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox...
🔗 CVE IDs covered (1)
📋 Description
Same-origin policy bypass in the WebExtensions component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
🔗 References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2026-100803
- https://bugzilla.mozilla.org/show_bug.cgi?id=2057988
- https://www.mozilla.org/security/advisories/mfsa2026-100
- https://www.mozilla.org/security/advisories/mfsa2026-97
- https://www.mozilla.org/security/advisories/mfsa2026-98
- https://www.mozilla.org/security/advisories/mfsa2026-99
- https://www.mozilla.org/security/advisories/mfsa2026-101
- https://www.mozilla.org/security/advisories/mfsa2026-102
- https://www.mozilla.org/security/advisories/mfsa2026-103
- https://github.com/advisories/GHSA-9m3c-9jr3-3cgr