CVE-2026-16395
A flaw in how the software handles numbers can cause an integer overflow within the audio and video components. This error can lead to unpredictable behavior or system instability.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of Mozilla Firefox and Mozilla Thunderbird are affected by this vulnerability.
Real-world impact
An attacker could potentially exploit this flaw to cause a crash or execute unauthorized actions by sending specially crafted audio or video content.
Why this severity
This is a critical vulnerability because it can be exploited remotely over a network without any user interaction or special privileges, potentially affecting the confidentiality, integrity, and availability of the system.
What to do about it
- 011. Upgrade Mozilla Firefox to version 153 or later.
- 022. Upgrade Mozilla Thunderbird to version 153 or later.
NVD-referenced vendor advisory
Timeline
- Jul 21, 2026 · 12d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- bugzilla.mozilla.org/show_bug.cgipermissions required
- mozilla.org/security/advisories/mfsa202…vendor advisory
- mozilla.org/security/advisories/mfsa202…