CVE-2026-16373
7.5Mozilla · Firefox for Android
An information disclosure vulnerability exists in the Privacy component of Firefox for Android, allowing unauthenticated remote attackers to compromise sensitive data.
Executive summary
An information disclosure vulnerability in the Privacy component of Firefox for Android allows unauthenticated remote attackers to expose sensitive user data.
Vulnerability
This is an information disclosure vulnerability residing within the Privacy component, triggered remotely via network access without requiring user interaction or authentication privileges.
Business impact
Successful exploitation of this vulnerability can lead to unauthorized exposure of sensitive user data, potentially resulting in privacy violations and regulatory compliance breaches. Given the high CVSS score of 7.5, the flaw presents significant risk due to its low attack complexity and the absence of required privileges for remote exploitation.
Remediation
Immediate Action: Update Mozilla Firefox for Android to version 153 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor mobile endpoint activity and review application logs for anomalous data access patterns originating from unauthenticated sources.
Compensating Controls: Enforce enterprise mobile device management policies to restrict untrusted network connections while awaiting device updates.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Security teams must treat this high severity vulnerability with urgency by deploying the fixed version across all applicable mobile devices immediately. Prompt patching is essential to prevent potential information disclosure and protect sensitive user privacy.
More Mozilla CVEs
Sources
Originally found and disclosed by Satoki Tsuji, per the CVE Program record.