Firefox 157 fixes high-impact flaws, including sandbox escapes
On 29 September 2026, Mozilla publishes MFSA 2026-97 for Firefox 157. The stated impact is high. The advisory names sandbox escapes and use-after-free bugs. It does not say these flaws are being exploited.

Original AI-generated illustration · SecuFocus
At a glance
Key points
This is a patch advisory, not a report of an ongoing attack. Updating is the move. We did not replay the flaws.
What changes
MFSA 2026-97, announced on 29 September 2026, covers Firefox 157. Mozilla rates the impact high. The advisory lists separate CVEs, including CVE-2026-100758, a sandbox escape in DOM navigation, and CVE-2026-100760, a sandbox escape in process sandboxing.
Other entries describe use-after-free bugs in the widget, WebGPU or WebAssembly components. Mozilla says it no longer rolls internally found memory-safety bugs into a single CVE. Each bug gets its own advisory entry.
What can leave
A browser flaw, if triggered, can read or run in the page context, sometimes beyond the sandbox. The advisory names no malicious site and no campaign. Updating removes the unfixed version from the picture. It does not say who already visited what.
What we did not check
We did not run Firefox 157, and we did not attempt the CVEs. The advisory does not say exploited. Do not turn it into an active-attack alert.
The choice
If Firefox is your browser, install 157, or the matching ESR build if you stay on a long-term branch. The 29 September set also covers ESR releases. Check the version in About, not only whether an update is offered.
Check and explore
Sources for this article
Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.
- MFSA 2026-97, Mozilla ↗mozilla.org ·
This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.
Cite this article
Keep this reference with the article when you save or share it.