CVE-2026-16351 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-16351 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16351 is a use-after-free sandbox escape vulnerability in the DOM Navigation component of Mozilla Firefox and Mozilla Thunderbird.
Technical Detail
The flaw results from unsafe handling of an object after its memory has been freed within the DOM Navigation component. An attacker could trigger the condition by causing a victim to process attacker-controlled web content, potentially allowing code execution outside the browser or mail client content sandbox. Successful exploitation could enable remote code execution in the context of the affected application and reduce the protection provided by Mozilla's sandboxing architecture.
Exploitation Status
No known exploit has been reported, and CVE-2026-16351 is not listed in CISA's Known Exploited Vulnerabilities catalog as of July 28, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Apply Mozilla security updates as a high priority. Upgrade Firefox to version 153 or later, Firefox ESR to version 115.38 or 140.13 or later within their respective release branches, and Thunderbird to version 153 or Thunderbird ESR 140.13 or later. No workaround or specific detection indicators have been provided; organizations should verify installed versions across managed endpoints and restrict use of unsupported Firefox and Thunderbird releases.