CVE-2026-16349
9.8Mozilla · Firefox, Thunderbird
A same-origin policy bypass exists in the DOM Navigation component of Mozilla Firefox and Thunderbird, allowing unauthenticated attackers to potentially compromise user data and system integrity.
Executive summary
Mozilla Firefox and Thunderbird are affected by a critical same-origin policy bypass vulnerability that permits unauthenticated remote attackers to achieve full system compromise.
Vulnerability
This is a same-origin policy bypass flaw located within the DOM Navigation component. The vulnerability allows an unauthenticated, remote attacker to bypass security boundaries, leading to unauthorized access, data manipulation, or arbitrary code execution.
Business impact
The CVSS score of 9.8 reflects the extreme severity of this flaw, as it is network-exploitable with no authentication or user interaction required. Successful exploitation could lead to total system compromise, theft of sensitive session data, and the potential for lateral movement within an organization, posing a significant threat to information security and operational continuity.
Remediation
Immediate Action: Update all instances of Mozilla Firefox and Thunderbird to version 153 or the corresponding ESR versions (115.38 or 140.13) immediately to patch the navigation component.
Proactive Monitoring: Monitor network traffic for unusual DOM-related activity or unexpected navigation patterns originating from external sources that may indicate attempted exploitation.
Compensating Controls: Ensure that browser security settings are strictly enforced via Group Policy or configuration management, and utilize endpoint detection and response tools to identify anomalous browser process behavior.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical CVSS severity and the nature of the same-origin policy bypass, this vulnerability represents a high-risk entry point for attackers to compromise end-user workstations. Security teams must prioritize the deployment of the Mozilla security updates across the entire fleet to eliminate this attack vector. There is no viable long-term mitigation other than applying the vendor-provided patches, and immediate action is required to maintain a secure posture.
More Mozilla CVEs
Sources
Originally found and disclosed by Tran Quac, per the CVE Program record.