CVE-2026-16396
8.8Mozilla · Firefox
A privilege escalation vulnerability in WebExtensions affects Mozilla Firefox and Thunderbird, allowing an unauthenticated attacker with user interaction to achieve high impact.
Executive summary
A privilege escalation vulnerability in WebExtensions affects Mozilla Firefox and Thunderbird, posing a high risk of total system compromise through malicious extension abuse.
Vulnerability
This vulnerability is a privilege escalation flaw within the WebExtensions component, triggered via network attack vectors requiring user interaction from an unauthenticated user.
Business impact
A successful exploit of this vulnerability could lead to a total compromise of confidentiality, integrity, and availability within the context of the application. Given the high CVSS score of 8.8, successful attacks could allow malicious extensions to bypass security boundaries, potentially resulting in unauthorized data access, system manipulation, or arbitrary code execution on client machines.
Remediation
Immediate Action: Update Mozilla Firefox to version 153 or later, and Mozilla Firefox ESR and Thunderbird to version 140.13 or later.
Proactive Monitoring: Monitor client environments for unauthorized WebExtension installations or suspicious browser behavior.
Compensating Controls: Enforce enterprise policies that restrict or disable unauthorized WebExtension installations until patches can be deployed.
Exploitation status
Public Exploit Available: No - unknown
Analyst recommendation
Organizations must treat this high severity flaw with urgency and deploy the latest Mozilla updates immediately. Prompt patching of Firefox and Thunderbird deployments will neutralize the privilege escalation vector and prevent potential extension-based attacks.
More Mozilla CVEs
Sources
Originally found and disclosed by Quy Pham, per the CVE Program record.