CVE-2026-100828: Mitigation bypass in the Bookmarks & History component
Mitigation bypass in the Bookmarks & History component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 157 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.4 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 153.4 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 157
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-100756
- CVE-2026-100757
- CVE-2026-100758
- CVE-2026-100759
- CVE-2026-100760
- CVE-2026-100761
- CVE-2026-100762
- CVE-2026-100763
- CVE-2026-100764
- CVE-2026-100765
- CVE-2026-100766
- CVE-2026-100767
- CVE-2026-100768
- CVE-2026-100769
- CVE-2026-100770
- CVE-2026-100771
- CVE-2026-100772
- CVE-2026-100773
- CVE-2026-100774
- CVE-2026-100775
- CVE-2026-100776
- CVE-2026-100777
- CVE-2026-100778
- CVE-2026-100779
- CVE-2026-100780
- CVE-2026-100781
- CVE-2026-100782
- CVE-2026-100783
- CVE-2026-100784
- CVE-2026-100785
- CVE-2026-100786
- CVE-2026-100787
- CVE-2026-100788
- CVE-2026-100789
- CVE-2026-100790
- CVE-2026-100791
- CVE-2026-100792
- CVE-2026-100793
- CVE-2026-100794
- CVE-2026-96869
- CVE-2026-100795
- CVE-2026-100796
- CVE-2026-100797
- CVE-2026-100798
- CVE-2026-100799
- CVE-2026-100800
- CVE-2026-100801
- CVE-2026-100802
- CVE-2026-100803
- CVE-2026-100804
- CVE-2026-100805
- CVE-2026-100806
- CVE-2026-100807
- CVE-2026-100808
- CVE-2026-100809
- CVE-2026-100810
- CVE-2026-100811
- CVE-2026-100812
- CVE-2026-100813
- CVE-2026-100814
- CVE-2026-100815
- CVE-2026-100816
- CVE-2026-100817
- CVE-2026-100818
- CVE-2026-100819
- CVE-2026-100820
- CVE-2026-100821
- CVE-2026-100822
- CVE-2026-100823
- CVE-2026-100824
- CVE-2026-100825
- CVE-2026-100826
- CVE-2026-100828
- CVE-2026-100829
- CVE-2026-100830
- CVE-2026-100831
- CVE-2026-100832
Frequently Asked Questions
Are affected versions or interim mitigations specified in the available record?
No. The record identifies Mozilla Firefox and Mozilla Firefox ESR but does not provide affected-version ranges, fixed versions, exploit prerequisites, or workaround guidance; the listed Mozilla advisories and Bugzilla reference are the available vendor sources.