CVE-2026-16388

9.8

Mozilla · Firefox, Thunderbird

A sandbox escape vulnerability exists within the DOM Networking component of Firefox and Thunderbird, allowing for potential system compromise.

Executive summary

A critical sandbox escape vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated attackers to achieve full system impact.

Vulnerability

This vulnerability resides in the DOM Networking component, where a failure in the sandbox environment permits an unauthenticated attacker to escape isolation and execute arbitrary code.

Business impact

The vulnerability carries a CVSS score of 9.8, indicating a critical risk of total system compromise. Successful exploitation could lead to unauthorized access to sensitive user data, remote code execution, and potential lateral movement within the network, resulting in significant operational and security repercussions for the organization.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately.

Proactive Monitoring: Review endpoint and network logs for unusual process execution patterns or unexpected outbound network traffic originating from browser or mail client processes.

Compensating Controls: Ensure that endpoint protection software is active and configured to detect anomalous sandbox-breaking behavior, and enforce the principle of least privilege for user accounts to limit the potential reach of an exploited application.

Exploitation status

Public Exploit Available: No confirmed public exploit is available.

Analyst recommendation

Due to the critical nature of this flaw and the potential for complete system compromise without user interaction, organizations must prioritize the deployment of the provided security updates. Patching Firefox and Thunderbird to version 153 is the only effective way to mitigate this high-risk vulnerability.

More Mozilla CVEs

Sources

Originally found and disclosed by Yaqoub Aldurayhim, per the CVE Program record.