CVE-2026-16368
9.8Mozilla · Firefox, Thunderbird
Mozilla Firefox and Thunderbird contain an incorrect boundary condition in the WebAssembly component, which could allow for remote code execution.
Executive summary
A critical vulnerability in the WebAssembly component of Mozilla Firefox and Thunderbird allows unauthenticated attackers to potentially achieve remote code execution.
Vulnerability
This flaw involves incorrect boundary conditions within the JavaScript WebAssembly engine. The vulnerability is exploitable by an unauthenticated, remote attacker who does not require user interaction to trigger the condition.
Business impact
The CVSS score of 9.8 reflects the high risk posed by this vulnerability, as it allows for full compromise of the application and potentially the underlying host system. Successful exploitation could lead to unauthorized data access, system disruption, or the installation of malicious software, posing a severe threat to operational integrity and organizational data security.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 153 or later, or apply the Firefox ESR 140.13 update, to incorporate the necessary security patches.
Proactive Monitoring: Monitor network traffic and endpoint logs for unusual JavaScript execution patterns or unexpected spikes in CPU usage associated with the browser process.
Compensating Controls: While no direct virtual patch exists, ensuring that browsers are run in constrained, least-privilege environments can help limit the impact of a potential sandbox escape or code execution.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This is a critical-severity vulnerability that requires immediate attention from all system administrators and end users. Because the vulnerability is automatable and requires no user interaction, the risk of automated exploitation attempts is significant. Organizations should prioritize the deployment of the provided updates across all workstation and server environments to mitigate this risk.
More Mozilla CVEs
Sources
Originally found and disclosed by Nebula Security, per the CVE Program record.