CVE-2026-16354
7.5Mozilla · Firefox
Information disclosure vulnerability in the Graphics: ImageLib component affecting Mozilla Firefox and Thunderbird.
Executive summary
An unauthenticated remote information disclosure vulnerability in the Graphics ImageLib component of Mozilla Firefox and Thunderbird poses a high risk to data confidentiality.
Vulnerability
This is an information disclosure vulnerability located in the Graphics: ImageLib component, accessible over the network without requiring user interaction or authentication privileges.
Business impact
A successful exploit allows unauthorized remote actors to read sensitive information, potentially compromising internal data confidentiality. With a CVSS score of 7.5, the severity is high due to the network vector and the complete lack of required privileges or user interaction for successful exploitation.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 153, Firefox ESR 115.38, Firefox ESR 140.13, or later.
Proactive Monitoring: Monitor network and application access logs for unusual data retrieval patterns or suspicious traffic originating from untrusted sources.
Compensating Controls: Ensure network perimeter defenses are configured to restrict unauthorized inbound access to endpoints hosting vulnerable browser instances where applicable.
Exploitation status
Public Exploit Available: No (no confirmed public exploit or weaponized module currently available).
Analyst recommendation
Given the high severity score and the low barrier to entry for potential attackers, organizations must prioritize updating affected software installations. Applying the vendor patches immediately will neutralize the information disclosure vector and safeguard sensitive data assets from unauthorized access.
More Mozilla CVEs
Sources
Originally found and disclosed by satyamasd, per the CVE Program record.