CVE-2026-16400

7.5

Mozilla · Firefox and Thunderbird

An information disclosure vulnerability exists in the DOM security component of Mozilla Firefox and Thunderbird prior to version 153, allowing unauthenticated attackers to expose sensitive data.

Executive summary

An information disclosure vulnerability in Mozilla Firefox and Thunderbird allows unauthenticated remote attackers to compromise sensitive data.

Vulnerability

This information disclosure flaw resides within the Document Object Model security component. It can be triggered remotely by an unauthenticated attacker over network vectors without requiring user interaction.

Business impact

Successful exploitation of this vulnerability can lead to the exposure of confidential data, potentially compromising internal organizational information or user privacy. Given the high CVSS score of 7.5, the severity is elevated due to the ease of network exploitation and the lack of required authentication or user interaction.

Remediation

Immediate Action: Update Mozilla Firefox and Thunderbird to version 153 or later to apply the official vendor patch.

Proactive Monitoring: Monitor network perimeter traffic and application logs for unusual data access patterns or anomalous requests targeting client applications.

Compensating Controls: Utilize endpoint protection platforms and network security monitoring to detect and block abnormal data exfiltration attempts.

Exploitation status

Public Exploit Available: No (false)

Analyst recommendation

Organizations should treat this high severity vulnerability with urgency by deploying the updated software versions across all managed endpoints. Prioritizing the patch application ensures that potential data exposure risks are mitigated before public exploits emerge.

More Mozilla CVEs

Sources

Originally found and disclosed by Rintaro Kawasugi, per the CVE Program record.