CVE-2026-16349
CVE-2026-16349 is a critical vulnerability allowing attackers to bypass the same-origin policy in Firefox and Thunderbird's navigation component, potentially enabling unauthorized access to sensitive data. It was fixed in Firefox 153, Firefox ESR 115.38/140.13, and Thunderbird 153/140.13.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Firefox 152 or earlier, Firefox ESR 115.37 or earlier/140.12 or earlier, and Thunderbird 152 or earlier/140.12 or earlier.
Real-world impact
Attackers could exploit this to access restricted resources without proper authorization.
Why this severity
CVSS 9.8 (critical): High confidence in exploitation, leading to full data compromise.
What to do about it
- 01Upgrade Firefox to version 153 or later.
- 02Upgrade Firefox ESR to version 115.38 or 140.13 or later.
- 03Upgrade Thunderbird to version 153 or 140.13 or later.
NVD description stating the vulnerability was fixed in specified versions.
Timeline
- Jul 21, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 24, 2026 · 9d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- bugzilla.mozilla.org/show_bug.cgipermissions required
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory