CVE-2026-16352 -- CVSS 9.8 Vulnerability Briefing
CVE-2026-16352 | CVSS 9.8 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16352 is a use-after-free vulnerability in Mozilla Firefox and Thunderbird Disability Access APIs that can allow a sandbox escape.
Technical Detail
The flaw results from unsafe handling of object lifetime within the Disability Access APIs component, creating a use-after-free condition. An attacker who can trigger the vulnerable condition may escape the browser or mail client sandbox and access resources beyond the intended restrictions of the sandboxed process. Public technical details describing the precise trigger conditions have not been confirmed.
Exploitation Status
No known exploit has been reported, and CISA has not listed this vulnerability in its Known Exploited Vulnerabilities catalog as of July 28, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize updates for Mozilla Firefox and Thunderbird, particularly on systems where browsers or email clients process untrusted web or message content. Upgrade Firefox to version 153 or later, Firefox ESR to 115.38 or 140.13 or later within the applicable ESR branch, Thunderbird to version 153 or later, or Thunderbird 140 or later. No vendor-supported workaround or specific detection signal has been confirmed; organizations should verify deployed versions, use centralized patch-management reporting, and investigate unexpected browser or Thunderbird child-process behavior where endpoint telemetry is available.