CVE-2026-16362

8.8

Mozilla · Firefox

A use-after-free vulnerability exists in the WebRTC audio and video component of Mozilla Firefox and Thunderbird, allowing potential remote code execution via user interaction.

Executive summary

A high-severity use-after-free vulnerability in Mozilla Firefox and Thunderbird allows remote code execution when a user interacts with malicious content.

Vulnerability

This flaw is a use-after-free vulnerability in the WebRTC Audio and Video component, which can be triggered by an unauthenticated attacker requiring user interaction, such as visiting a crafted webpage.

Business impact

A successful exploit of this vulnerability can lead to total compromise of the affected client machine, allowing an attacker to execute arbitrary code with the privileges of the logged-in user. This poses significant risks of data confidentiality breaches, integrity loss, and system availability disruption. The CVSS score of 8.8 reflects the high severity of the potential impact, though mitigated slightly by the requirement for user interaction.

Remediation

Immediate Action: Update Mozilla Firefox to version 153 or later, Firefox ESR to 140.13 or later, and apply corresponding patches for Thunderbird immediately.

Proactive Monitoring: Monitor endpoint telemetry for anomalous browser subprocess crashes, unexpected child process terminations, or unauthorized child process spawns that could indicate exploitation attempts.

Compensating Controls: Enforce strict browsing policies and utilize network defenses to block access to known malicious domains or untrusted WebRTC endpoints.

Exploitation status

Public Exploit Available: No - As of Jul 21, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability.

Analyst recommendation

Organizations must prioritize deploying the official vendor patches for Firefox and Thunderbird across all managed endpoints. Due to the high severity and potential for total system compromise stemming from memory management flaws, administrators should ensure updates are applied rapidly to mitigate the risk of zero-day or weaponized follow-up exploits.

More Mozilla CVEs

Sources

Originally found and disclosed by crixer, per the CVE Program record.