CVE-2026-16371

9.8

Mozilla · Firefox, Thunderbird

A critical privilege escalation vulnerability exists in the DOM Navigation component of Mozilla Firefox and Thunderbird, allowing potential full system compromise.

Executive summary

A critical privilege escalation vulnerability in the DOM Navigation component of Mozilla Firefox and Thunderbird poses a severe risk of total system compromise for unpatched users.

Vulnerability

This flaw involves a privilege escalation vulnerability within the DOM Navigation component. Based on the CVSS vector, the vulnerability can be triggered by an unauthenticated attacker, though it requires user interaction to execute.

Business impact

The vulnerability carries a critical CVSS score of 9.8, indicating the potential for total loss of confidentiality, integrity, and availability. Successful exploitation allows an attacker to bypass security boundaries, potentially leading to unauthorized data exfiltration, malware installation, or full control over the affected browser session and underlying system.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to version 153 or the ESR version 140.13 immediately to apply the necessary security patches.

Proactive Monitoring: Security teams should monitor for unusual browser process behavior or unexpected network connections originating from browser-based navigation events.

Compensating Controls: While no direct virtual patch exists for this specific DOM flaw, maintaining endpoint detection and response (EDR) solutions can help identify and block suspicious shell executions or privilege escalation attempts resulting from malicious browser activity.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical severity rating and the potential for complete system compromise, organizations must prioritize patching all instances of Firefox and Thunderbird. Administrators should utilize enterprise deployment tools to force the update to version 153 or 140.13 across all workstations to mitigate this risk immediately.

More Mozilla CVEs

Sources

Originally found and disclosed by Steven Julian, per the CVE Program record.