CVE-2026-16351
9.8Mozilla · Firefox, Thunderbird
A use-after-free vulnerability in the DOM Navigation component allows for sandbox escapes in Mozilla Firefox and Thunderbird.
Executive summary
A critical use-after-free vulnerability in the DOM Navigation component of Mozilla Firefox and Thunderbird could allow an unauthenticated attacker to achieve a sandbox escape and full system compromise.
Vulnerability
This is a use-after-free memory corruption flaw located within the DOM Navigation component. The vulnerability is exploitable by an unauthenticated remote attacker with no user interaction required, as indicated by the CVSS vector.
Business impact
Successful exploitation of this vulnerability permits an attacker to escape the browser sandbox, potentially leading to arbitrary code execution on the underlying host system. Given the CVSS score of 9.8, this represents a critical risk to data confidentiality, integrity, and system availability, necessitating immediate remediation across the enterprise.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Thunderbird to the specified fixed versions: Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, or Thunderbird 153 and 140.13 respectively.
Proactive Monitoring: Review endpoint security logs for unexpected process spawns or unauthorized file access originating from the web browser or mail client processes.
Compensating Controls: Ensure that all browser-based activity is segmented where possible and that endpoint protection platforms are configured to detect and block memory-based exploitation attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The severity of this vulnerability is absolute, as it allows for a complete bypass of the browser security model. Organizations must prioritize the deployment of the vendor-provided patches across all workstations and servers running these applications to eliminate the risk of remote code execution.
More Mozilla CVEs
Sources
Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.