CVE-2026-16396

8.8

Mozilla · Firefox

A privilege escalation vulnerability in WebExtensions affects Mozilla Firefox and Thunderbird, allowing an unauthenticated attacker with user interaction to achieve high impact.

Executive summary

A privilege escalation vulnerability in WebExtensions affects Mozilla Firefox and Thunderbird, posing a high risk of total system compromise through malicious extension abuse.

Vulnerability

This vulnerability is a privilege escalation flaw within the WebExtensions component, triggered via network attack vectors requiring user interaction from an unauthenticated user.

Business impact

A successful exploit of this vulnerability could lead to a total compromise of confidentiality, integrity, and availability within the context of the application. Given the high CVSS score of 8.8, successful attacks could allow malicious extensions to bypass security boundaries, potentially resulting in unauthorized data access, system manipulation, or arbitrary code execution on client machines.

Remediation

Immediate Action: Update Mozilla Firefox to version 153 or later, and Mozilla Firefox ESR and Thunderbird to version 140.13 or later.

Proactive Monitoring: Monitor client environments for unauthorized WebExtension installations or suspicious browser behavior.

Compensating Controls: Enforce enterprise policies that restrict or disable unauthorized WebExtension installations until patches can be deployed.

Exploitation status

Public Exploit Available: No - unknown

Analyst recommendation

Organizations must treat this high severity flaw with urgency and deploy the latest Mozilla updates immediately. Prompt patching of Firefox and Thunderbird deployments will neutralize the privilege escalation vector and prevent potential extension-based attacks.

More Mozilla CVEs

Sources

Originally found and disclosed by Quy Pham, per the CVE Program record.