CVE-2026-16352

9.8

Mozilla · Firefox, Thunderbird

A use-after-free vulnerability in the Disability Access APIs component of Mozilla Firefox and Thunderbird allows for a sandbox escape.

Executive summary

A critical use-after-free vulnerability in Mozilla Firefox and Thunderbird allows an unauthenticated, remote attacker to trigger a sandbox escape and potentially achieve full system compromise.

Vulnerability

This is a use-after-free flaw within the Disability Access APIs component, which can be triggered by an unauthenticated remote attacker. The vulnerability permits a sandbox escape, granting the attacker the ability to execute arbitrary code outside the restricted browser environment.

Business impact

The CVSS score of 9.8 reflects the extreme severity of this flaw, as it requires no user interaction or authentication to trigger. Successful exploitation could lead to total system compromise, including the unauthorized exfiltration of sensitive data, installation of malware, or complete loss of system availability.

Remediation

Immediate Action: Apply the vendor-provided security updates immediately by upgrading Mozilla Firefox and Thunderbird to the identified fixed versions (115.38, 140.13, or 153, depending on the specific release channel).

Proactive Monitoring: Review endpoint security logs for anomalous processes or unexpected memory usage patterns associated with the browser or email client.

Compensating Controls: While no specific WAF rule can prevent a local use-after-free, ensure that endpoint detection and response (EDR) solutions are configured to monitor for suspicious child processes spawned by browser or mail client executables.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high CVSS score and the potential for a sandbox escape make this vulnerability an urgent priority for all organizations using Mozilla products. IT administrators should prioritize the deployment of the provided security patches across all affected workstations and servers to eliminate the risk of remote code execution.

More Mozilla CVEs

Sources

Originally found and disclosed by Oskar L, per the CVE Program record.