CVE-2026-16367
10.0Mozilla · Firefox, Thunderbird
A sandbox escape vulnerability exists in the Disability Access APIs component of Mozilla Firefox and Thunderbird due to an invalid pointer, allowing for potential system compromise.
Executive summary
A critical sandbox escape vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to achieve full system compromise.
Vulnerability
The vulnerability is a sandbox escape flaw caused by an invalid pointer in the Disability Access APIs component. It requires no authentication and no user interaction to trigger, making it an automatable attack vector.
Business impact
Successful exploitation of this vulnerability allows an attacker to break out of the browser sandbox and execute arbitrary code with the privileges of the application. Given the CVSS score of 10.0, this represents a total compromise of system confidentiality, integrity, and availability. Organizations face significant risks including data theft, malware installation, and lateral movement within the network.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately to apply the vendor-provided patch.
Proactive Monitoring: Review system and application logs for abnormal process behavior or unexpected crashes within the browser environment.
Compensating Controls: While browser-based sandbox escapes are difficult to block via perimeter tools, ensure that endpoint detection and response (EDR) solutions are active to identify and contain unauthorized child processes spawned by the browser.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the critical nature of this sandbox escape and the high CVSS severity score, immediate patching is required. Organizations should prioritize the deployment of Firefox and Thunderbird version 153 across all endpoints to eliminate this high-risk attack surface.
More Mozilla CVEs
Sources
Originally found and disclosed by Oskar L, per the CVE Program record.