CVE-2026-16358
CVE-2026-16358 is a critical site isolation vulnerability in Firefox's WebRender graphics component, allowing potential attacks to bypass security boundaries. It was fixed in Firefox 153, Firefox ESR 115.38/140.13, and Thunderbird 153/140.13.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Firefox (versions <153), Firefox ESR (versions <115.38 or <140.13), and Thunderbird (versions <153 or <140.13)
Real-world impact
Attackers could exploit this to compromise user data or system integrity by breaking isolation between trusted and untrusted web content.
Why this severity
CVSS 9.8 (critical): High risk due to network accessibility, low attack complexity, and full impact on confidentiality, integrity, and availability.
What to do about it
- 01Upgrade Firefox to version 153 or later.
- 02Update Firefox ESR to version 115.38 or 140.13.
- 03Upgrade Thunderbird to version 153 or 140.13.
NVD-referenced vendor advisory (fixed versions listed in NVD description)
Timeline
- Jul 21, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 24, 2026 · 9d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- bugzilla.mozilla.org/show_bug.cgipermissions required
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…vendor advisory