CVE-2026-16400
7.5Mozilla · Firefox and Thunderbird
An information disclosure vulnerability exists in the DOM security component of Mozilla Firefox and Thunderbird prior to version 153, allowing unauthenticated attackers to expose sensitive data.
Executive summary
An information disclosure vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to compromise sensitive data.
Vulnerability
This information disclosure flaw resides within the Document Object Model security component. It can be triggered remotely by an unauthenticated attacker over network vectors without requiring user interaction.
Business impact
Successful exploitation of this vulnerability can lead to the exposure of confidential data, potentially compromising internal organizational information or user privacy. Given the high CVSS score of 7.5, the severity is elevated due to the ease of network exploitation and the lack of required authentication or user interaction.
Remediation
Immediate Action: Update Mozilla Firefox and Thunderbird to version 153 or later to apply the official vendor patch.
Proactive Monitoring: Monitor network perimeter traffic and application logs for unusual data access patterns or anomalous requests targeting client applications.
Compensating Controls: Utilize endpoint protection platforms and network security monitoring to detect and block abnormal data exfiltration attempts.
Exploitation status
Public Exploit Available: No (false)
Analyst recommendation
Organizations should treat this high severity vulnerability with urgency by deploying the updated software versions across all managed endpoints. Prioritizing the patch application ensures that potential data exposure risks are mitigated before public exploits emerge.
More Mozilla CVEs
Sources
Originally found and disclosed by Rintaro Kawasugi, per the CVE Program record.