CVE-2026-16367 -- CVSS 10.0 Vulnerability Briefing
CVE-2026-16367 | CVSS 10.0 (Critical) | Exploit: No known exploit
What Is It
CVE-2026-16367 is a critical sandbox escape vulnerability in Mozilla Firefox and Mozilla Thunderbird involving an invalid pointer in the Disability Access APIs component.
Technical Detail
The flaw arises from invalid pointer handling within the Disability Access APIs component. An attacker may be able to trigger the issue through crafted web content or content processed by the affected applications, potentially escaping the browser or mail client sandbox. Successful exploitation could allow code execution outside the intended sandbox boundary, increasing the impact of a separate in-browser or application-level compromise.
Exploitation Status
No known exploit has been reported for this vulnerability. CVE-2026-16367 is not listed in CISA's Known Exploited Vulnerabilities Catalog as of July 28, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Update Firefox and Thunderbird to version 153 or later, which includes the vendor fix. Prioritize remediation on systems that routinely access untrusted websites, email content, attachments, or links. No workaround, specific detection signature, or confirmed exploitation activity has been published; organizations should monitor Mozilla security advisories and endpoint telemetry for unusual child-process behavior or unexpected code execution originating from Firefox or Thunderbird.