Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-100758 is a critical sandbox escape vulnerability (CVSS 9.6) affecting Firefox and Thunderbird's DOM Navigation component. Sandbox escapes are particularly dangerous because they allow attackers to break out of the browser's security isolation layer, potentially gaining direct access to the underlying system. This vulnerability affects multiple Firefox versions (157, ESR 115.42, ESR 140.17, ESR 153.4) and Thunderbird versions (140.17, 153.4, 157), impacting millions of users who rely on these applications for web browsing and email. The vulnerability could enable arbitrary code execution if successfully exploited, making it a critical concern for both individual users and enterprise environments where Firefox and Thunderbird are deployed.
While this CVE currently shows zero matching Casky skills due to missing MITRE ATT&CK technique mapping, practitioners using Casky.ai with Claude's extended reasoning capabilities would benefit from monitoring for exploitation patterns typically associated with sandbox escape attacks. Organizations should focus detection efforts on suspicious DOM manipulation attempts, unusual JavaScript execution patterns, and memory access anomalies that could indicate exploitation attempts. Security teams should prioritize patching affected systems immediately and monitor for indicators of compromise including unexpected process execution, unauthorized file access, or suspicious network connections originating from Firefox or Thunderbird processes. As threat intelligence emerges and technique mappings are refined, Casky's skill library can be leveraged to identify the attack chains and behavioral signatures that precede successful sandbox escape exploitations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-100758. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation