{"id":"CVE-2026-100800","published":"2026-09-29T13:17:45.073","lastModified":"2026-09-30T04:18:13.863","description":"Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.","cvssScore":9.6,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=2056767","tags":[]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-100/","tags":[]},{"url":"https://www.mozilla.org/security/advisories/mfsa2026-97/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}