CVE-2026-16378

7.5

Mozilla · Firefox

A vulnerability exists in the DOM Copy and Paste and Drag and Drop component of Mozilla Firefox and Thunderbird, allowing potential information disclosure.

Executive summary

A high-severity vulnerability in the DOM Copy & Paste and Drag & Drop component of Mozilla Firefox and Thunderbird allows unauthenticated network attackers to compromise confidentiality.

Vulnerability

This issue involves an improper handling flaw within the DOM Copy & Paste and Drag & Drop component, requiring no user interaction and no authentication from a network-based attacker.

Business impact

A successful exploit of this vulnerability could lead to unauthorized information disclosure, compromising sensitive user data processed by the browser. With a CVSS score of 7.5, the severity is classified as high due to the network attack vector and the absence of required privileges or user interaction, posing a significant risk to organizational data confidentiality.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to version 153 or later as specified by the vendor advisory.

Proactive Monitoring: Monitor client endpoints for anomalous browser behavior and review network traffic logs for unusual outbound data transfers.

Compensating Controls: Enforce strict browser security policies and utilize network monitoring tools to detect and block suspicious data exfiltration attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity rating and the potential for unauthorized data access, organizations must treat this vulnerability with urgency. Administrators should immediately apply the vendor-supplied updates to all affected Mozilla Firefox and Thunderbird installations to eliminate the underlying risk.

More Mozilla CVEs

Sources

Originally found and disclosed by Farhad Sajid Barbhuiya, per the CVE Program record.