CVE-2026-16365
9.8Mozilla · Firefox, Thunderbird
A privilege escalation vulnerability exists in the DOM Workers component of Mozilla Firefox and Thunderbird, potentially allowing full system compromise.
Executive summary
A critical privilege escalation vulnerability in the DOM Workers component of Mozilla Firefox and Thunderbird allows an unauthenticated attacker to achieve full system impact.
Vulnerability
This is a privilege escalation flaw located within the DOM Workers component. An unauthenticated attacker can trigger this issue to gain unauthorized control over the affected application, leading to a complete compromise of confidentiality, integrity, and availability.
Business impact
The vulnerability carries a CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation could allow an attacker to execute arbitrary code or gain unauthorized administrative access, resulting in significant data breaches, potential malware installation, and long-term loss of system integrity.
Remediation
Immediate Action: Update both Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately to apply the vendor-provided security patches.
Proactive Monitoring: Review browser and application access logs for unusual patterns or unexpected process execution originating from the DOM Workers component.
Compensating Controls: While no direct virtual patch exists, ensure that all endpoint security solutions are updated to detect anomalous behavior associated with browser-based exploitation.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical severity rating and the potential for full system compromise, organizations should prioritize patching Firefox and Thunderbird across all managed endpoints. Failure to remediate this vulnerability leaves systems exposed to potential remote code execution attacks that bypass standard security boundaries.
More Mozilla CVEs
Sources
Originally found and disclosed by Khanh Nguyen, per the CVE Program record.