CVE-2026-16354

7.5

Mozilla · Firefox

Information disclosure vulnerability in the Graphics: ImageLib component affecting Mozilla Firefox and Thunderbird.

Executive summary

An unauthenticated remote information disclosure vulnerability in the Graphics ImageLib component of Mozilla Firefox and Thunderbird poses a high risk to data confidentiality.

Vulnerability

This is an information disclosure vulnerability located in the Graphics: ImageLib component, accessible over the network without requiring user interaction or authentication privileges.

Business impact

A successful exploit allows unauthorized remote actors to read sensitive information, potentially compromising internal data confidentiality. With a CVSS score of 7.5, the severity is high due to the network vector and the complete lack of required privileges or user interaction for successful exploitation.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to version 153, Firefox ESR 115.38, Firefox ESR 140.13, or later.

Proactive Monitoring: Monitor network and application access logs for unusual data retrieval patterns or suspicious traffic originating from untrusted sources.

Compensating Controls: Ensure network perimeter defenses are configured to restrict unauthorized inbound access to endpoints hosting vulnerable browser instances where applicable.

Exploitation status

Public Exploit Available: No (no confirmed public exploit or weaponized module currently available).

Analyst recommendation

Given the high severity score and the low barrier to entry for potential attackers, organizations must prioritize updating affected software installations. Applying the vendor patches immediately will neutralize the information disclosure vector and safeguard sensitive data assets from unauthorized access.

More Mozilla CVEs

Sources

Originally found and disclosed by satyamasd, per the CVE Program record.