Sceawere
Vulnerability Detail
CVE-2026-100766UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Networking JAR Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 12h ago
- Vendor
- Mozilla
- Product
- Firefox
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Information disclosure in the Networking: JAR component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-29T13:17:40.837Z",
"pubdate": "2026-09-29T13:17:40.837Z",
"executiveSummary": "This vulnerability involves an information disclosure flaw located within the Networking: JAR component of the Firefox browser architecture.\nThe vulnerability allows unauthorized entities to gain access to sensitive information by exploiting improper handling of JAR (Java ARchive) files during network retrieval and processing.\nThe scope of impact includes potential unauthorized data access, which could be leveraged to extract cross-origin data or sensitive artifacts stored within the application context.\nAffected products include Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.\nThe risk implication is significant as it undermines the browser's origin-based security model, potentially allowing a malicious actor to bypass same-origin policies (SOP) via manipulated JAR file requests.\nExploitation generally requires a user to be directed to a malicious context or navigate to a specially crafted URI that triggers the flawed logic within the Networking: JAR subsystem.\nNo specific authentication is required for exploitation if the network-exposed component accepts untrusted input from external sources.",
"technicalDetails": "The vulnerability resides in the Networking: JAR component, which is responsible for fetching, parsing, and extracting resources contained within JAR file structures used by the browser. The root cause pertains to improper validation and boundary checking when parsing JAR archives, specifically concerning how the component handles nested or malformed entries that may reference files outside the intended archive scope.\nWhen a web application or a malicious site forces the browser to process a JAR file, the Networking: JAR component performs a series of operations, including decompressing and mapping file paths to URI structures. A vulnerability exists where the logic fails to enforce strict origin or path sanitization. Consequently, an attacker can manipulate the JAR metadata or internal structure to perform a path traversal or gain access to resources that should be restricted.\nThe attack flow typically follows this trajectory: 1. The attacker hosts a malicious JAR file or redirects a target to a server hosting a crafted archive. 2. The victim's browser initiates a network request for the resource. 3. The Networking: JAR component receives the resource and begins parsing the archive structure. 4. Due to the lack of sufficient sanitization, the parser follows malformed pointers or entry offsets that resolve to sensitive local or cross-origin data. 5. The information disclosure occurs when the component erroneously exposes the contents of the improperly accessed file to the requesting context.\nThis vulnerability is particularly dangerous as it targets the internal networking stack, meaning it operates at a layer below standard JavaScript security checks. Because the Networking: JAR component is deeply integrated into the browser's resource loading pipeline, it does not rely on traditional privilege escalation in the sense of remote code execution; rather, it facilitates a sophisticated data exfiltration attack. The vulnerability affects Firefox ESR 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17. The exposure is primarily network-based, as the browser automatically handles the parsing of these archives when triggered by URI navigation or embedded content references. No specific authentication or high-level privileges are required for an attacker to influence the component's state, provided the attacker can convince the victim to access the malicious or crafted resource."
}