CVE-2026-16373

7.5

Mozilla · Firefox for Android

An information disclosure vulnerability exists in the Privacy component of Firefox for Android, allowing unauthenticated remote attackers to compromise sensitive data.

Executive summary

An information disclosure vulnerability in the Privacy component of Firefox for Android allows unauthenticated remote attackers to expose sensitive user data.

Vulnerability

This is an information disclosure vulnerability residing within the Privacy component, triggered remotely via network access without requiring user interaction or authentication privileges.

Business impact

Successful exploitation of this vulnerability can lead to unauthorized exposure of sensitive user data, potentially resulting in privacy violations and regulatory compliance breaches. Given the high CVSS score of 7.5, the flaw presents significant risk due to its low attack complexity and the absence of required privileges for remote exploitation.

Remediation

Immediate Action: Update Mozilla Firefox for Android to version 153 or later as specified in the vendor advisory.

Proactive Monitoring: Monitor mobile endpoint activity and review application logs for anomalous data access patterns originating from unauthenticated sources.

Compensating Controls: Enforce enterprise mobile device management policies to restrict untrusted network connections while awaiting device updates.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Security teams must treat this high severity vulnerability with urgency by deploying the fixed version across all applicable mobile devices immediately. Prompt patching is essential to prevent potential information disclosure and protect sensitive user privacy.

More Mozilla CVEs

Sources

Originally found and disclosed by Satoki Tsuji, per the CVE Program record.