Mozilla Product Security Update Advisory
Mozilla has released security updates to address vulnerabilities in Firefox, Firefox ESR, and Thunderbird. Users of these products should update to the latest version.
Affected Versions
- CVE-2026-16349, CVE-2026-16350, CVE-2026-16351, CVE-2026-16352, CVE-2026-16353, CVE-2026-16354, CVE-2026-16355, CVE-2026-16356, CVE-2026-16357, CVE-2026-16360.
- Firefox versions earlier than 153.
- Firefox ESR versions earlier than 115.38.
- Firefox ESR versions earlier than 140.13.
- Thunderbird versions earlier than 153.
- Thunderbird versions earlier than 140.13.
- CVE-2026-16362, CVE-2026-16363, CVE-2026-16368, CVE-2026-16369.
- Firefox versions earlier than 153.
- Firefox ESR versions earlier than 140.13.
- Thunderbird versions earlier than 153.
- Thunderbird versions earlier than 140.13.
- CVE-2026-16364, CVE-2026-16365, CVE-2026-16366, CVE-2026-16367.
- Firefox versions prior to 153.
- Thunderbird versions earlier than 153.
Resolved Vulnerabilities
- Same-origin policy bypass vulnerability in the DOM Navigation component (CVE-2026-16349).
- Inappropriate boundary condition vulnerability in the Audio/Video cubeb component (CVE-2026-16350).
- Sandbox escape vulnerability in the DOM Navigation component (CVE-2026-16351).
- Sandbox escape vulnerabilities in the Access APIs component (CVE-2026-16352, CVE-2026-16356, CVE-2026-16367).
- Invalid pointer handling vulnerability in the DOM Bindings (WebIDL) component (CVE-2026-16353).
- Information disclosure vulnerability in the Graphics ImageLib component (CVE-2026-16354).
- A miscompilation vulnerability in the JIT component of the JavaScript engine (CVE-2026-16355).
- An improper boundary condition vulnerability in the graphics component (CVE-2026-16357).
- Memory safety vulnerability in Firefox, Firefox ESR, and Thunderbird (CVE-2026-16360).
- Use-after-free vulnerability in the WebRTC Audio/Video component (CVE-2026-16362).
- JIT decompilation vulnerability in the JavaScript WebAssembly component (CVE-2026-16363).
- Improper boundary condition vulnerability in the JavaScript WebAssembly component (CVE-2026-16368).
- Integer overflow vulnerability in the JavaScript WebAssembly component (CVE-2026-16369).
- Improper boundary condition vulnerability in the Audio/Video Playback component (CVE-2026-16364).
- Privilege escalation vulnerability in the DOM Workers component (CVE-2026-16365).
- Privilege escalation vulnerability in the DOM Navigation component (CVE-2026-16366).
Patch Information
Vulnerability Patches were provided in the latest update. Mozilla advises users to update to the latest version with the Vulnerability Patches, as outlined on the reference site.