CVE-2026-16402
9.8Mozilla · Firefox, Thunderbird
An integer overflow vulnerability exists in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, potentially allowing remote code execution.
Executive summary
A critical integer overflow vulnerability in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird enables unauthenticated remote code execution.
Vulnerability
This vulnerability is an integer overflow flaw located within the Graphics: ImageLib component. The vulnerability is exploitable by an unauthenticated remote attacker with no user interaction required.
Business impact
The flaw carries a CVSS score of 9.8, indicating a critical risk to organizational infrastructure. Successful exploitation allows an attacker to achieve total system compromise, potentially leading to unauthorized data access, the installation of malicious software, and complete loss of system integrity.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 153 or later immediately.
Proactive Monitoring: Monitor network traffic and endpoint logs for abnormal application crashes or unauthorized process executions associated with the browser or email client.
Compensating Controls: While no specific WAF rule can prevent this memory-level flaw, ensure that endpoint detection and response (EDR) solutions are configured to block suspicious child processes spawned by browser services.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical severity and the potential for full system compromise, organizations should prioritize the deployment of the version 153 update across all workstations and servers. Given that this vulnerability allows for remote execution without user interaction, prompt patching is the only effective defense against potential exploitation.
More Mozilla CVEs
Sources
Originally found and disclosed by Kai Martin, per the CVE Program record.