CVE-2026-100788 is an invalid-pointer bug in the JavaScript WebAssembly component shared by Mozilla Firefox and Thunderbird. WebAssembly is a browser technology that lets sites run compact, high-performance code alongside JavaScript. A bad pointer is a memory-safety failure: code can retain or use a reference that no longer points to valid data, creating conditions that can lead to a crash or, in the worst case, execution of attacker-controlled code.
Mozilla rates the issue high impact, while the supplied CVSS 3.1 data rates it 9.8. That difference is worth recording rather than smoothing over: Mozilla’s Firefox advisory does not publish a CVSS vector or explain the exploit chain. Public source metadata ties the fix to handling exceptions in WebAssembly and changing garbage-collection rooting of a throw-stub owner, but the restricted bug report leaves the exact faulty pointer, function and trigger unconfirmed.
A web page is the relevant starting point
Firefox is Mozilla’s open-source browser, used by individuals and in centrally managed desktop fleets. Firefox ESR is the long-support channel commonly chosen by schools, universities, businesses and other organisations that need stable, policy-managed browser deployments. Thunderbird is Mozilla’s cross-platform email, contact and calendar client, also deployed at scale on managed endpoints.
For Firefox, the plausible attacker position is clear: get a target to load a hostile website or web content capable of exercising WebAssembly. The supplied CVSS vector describes network reachability with no prior privileges or user interaction, but Mozilla has not documented a working attack sequence. Teams should therefore treat remote code execution as a potential outcome of exploiting this class of memory corruption, not as a vendor-confirmed end-to-end demonstration.
Thunderbird needs a more careful reading. Mozilla says scripting is disabled while an ordinary email is being read, so inherited Firefox-engine bugs generally cannot be exploited directly by simply sending a message. Its Thunderbird advisory still matters because browser or browser-like contexts available through the client may expose the engine. This is an endpoint risk, not a server-side mail-server flaw.
Fixed releases are available now
Mozilla fixed CVE-2026-100788 in Firefox 157, Firefox ESR 140.17 and 153.4, plus Thunderbird 157, 140.17 and 153.4. The advisories do not state a complete vulnerable-version range, and the available evidence does not establish whether Firefox ESR 115 was affected. The CVE record likewise identifies fixed points rather than a dependable full range.
Update Mozilla-provided installations to the applicable fixed release, and have Linux desktop teams verify that their distribution packages incorporate the fixes rather than assuming a matching upstream version is already installed. Prioritise managed Firefox and ESR fleets, especially users who browse external sites as part of research, customer support, finance, education or general office work. Update centrally managed Thunderbird deployments on the same schedule, while avoiding the misleading claim that any normal email is automatically an exploit vehicle.
No public exploitation signal so far
As of October 4, 2026, no confirmed in-the-wild exploitation, named campaign or victim reporting had surfaced. CVE-2026-100788 was not listed in CISA’s Known Exploited Vulnerabilities catalogue, and searches found no public proof of concept or exploit code. Those are useful prioritisation facts, not reasons to defer routine patching: public patches and release notes can make investigation easier after deployment.
This fix appeared among the same release activity as CVE-2026-100810, but it deserves its own change-ticket and validation because it affects a shared browser engine. Confirm actual installed versions, update, and watch for follow-on information; SecAlerts monitors an organisation’s actual software stack and alerts on new vulnerabilities affecting the products it runs.




