Mozilla Foundation Security Advisory 2026-68

Security Vulnerabilities fixed in Firefox 153

Announced
July 21, 2026
Impact
high
Products
Firefox
Fixed in
  • Firefox 153

#CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component

Reporter
Tran Quac
Impact
high
References

#CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component

Reporter
Tomoya Nakanishi
Impact
high
References

#CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component

Reporter
crixer
Impact
high
References

#CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component

Reporter
Yaqoub Aldurayhim
Impact
high
References

#CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
Oskar L
Impact
high
References

#CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component

Reporter
Nebula Security
Impact
high
References

#CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component

Reporter
stevej
Impact
high
References

#CVE-2026-16365: Privilege escalation in the DOM: Workers component

Reporter
Khanh Nguyen
Impact
high
References

#CVE-2026-16366: Privilege escalation in the DOM: Navigation component

Reporter
Khanh Nguyen
Impact
high
References

#CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component

Reporter
fedek
Impact
high
References

#CVE-2026-16354: Information disclosure in the Graphics: ImageLib component

Reporter
satyamasd
Impact
high
References

#CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component

Reporter
Oskar L
Impact
high
References

#CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component

Reporter
Nebula Security
Impact
high
References

#CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
Amy Burnett of OpenAI
Impact
high
References

#CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component

Reporter
Oskar L
Impact
high
References

#CVE-2026-16357: Incorrect boundary conditions in the Graphics component

Reporter
5up3rh3i
Impact
high
References

#CVE-2026-16370: Mitigation bypass in the DOM: Networking component

Reporter
tiebuchen
Impact
moderate
References

#CVE-2026-16371: Privilege escalation in the DOM: Navigation component

Reporter
stevej
Impact
moderate
References

#CVE-2026-16372: Privilege escalation in the DOM: Content Processes component

Reporter
Sajeeb Lohani
Impact
moderate
References

#CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android

Reporter
Satoki Tsuji
Impact
moderate
References

#CVE-2026-16374: Information disclosure in the Framework component in DevTools

Reporter
Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-16375: Site isolation issue in the Networking: HTTP component

Reporter
pakhunov.anton.n
Impact
moderate
References

#CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component

Reporter
Mihalis Haatainen
Impact
moderate
References

#CVE-2026-16377: Mitigation bypass in the PDF Viewer component

Reporter
Nikola Kojic
Impact
moderate
References

#CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component

Reporter
Farhad Sajid Barbhuiya
Impact
moderate
References

#CVE-2026-16379: Privilege escalation in the DOM: Content Processes component

Reporter
Shu Takahashi
Impact
moderate
References

#CVE-2026-16358: Site isolation issue in the Graphics: WebRender component

Reporter
Hcamael
Impact
moderate
References

#CVE-2026-16380: Mitigation bypass in the Networking component

Reporter
Rintaro Kawasugi
Impact
moderate
References

#CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component

Reporter
Rintaro Kawasugi
Impact
moderate
References

#CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-16383: Mitigation bypass in the DOM: Networking component

Reporter
Ibuki Sato and Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component

Reporter
5up3rh3i
Impact
moderate
References

#CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component

Reporter
5up3rh3i
Impact
moderate
References

#CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component

Reporter
5up3rh3i
Impact
moderate
References

#CVE-2026-16387: Site isolation issue in the Networking component

Reporter
Atsushi Sada
Impact
moderate
References

#CVE-2026-16388: Sandbox escape in the DOM: Networking component

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS

Reporter
Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-16390: Mitigation bypass in the Enterprise Policies component

Reporter
Souma Ohsawa
Impact
moderate
References

#CVE-2026-16391: Information disclosure in the Storage: IndexedDB component

Reporter
Tomoya Nakanishi
Impact
moderate
References

#CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
Gary Kwong
Impact
moderate
References

#CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component

Reporter
Atsushi Sada
Impact
moderate
References

#CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component

Reporter
Jacolon Walker
Impact
moderate
References

#CVE-2026-16394: Mitigation bypass in the DOM: Security component

Reporter
Nithissh
Impact
moderate
References

#CVE-2026-16395: Integer overflow in the Audio/Video component

Reporter
stevej
Impact
moderate
References

#CVE-2026-16396: Privilege escalation in WebExtensions

Reporter
Quy Pham
Impact
moderate
References

#CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android

Reporter
Hafiizh
Impact
moderate
References

#CVE-2026-16398: Site isolation issue in the Graphics component

Reporter
stevej
Impact
moderate
References

#CVE-2026-16399: Site isolation issue in the DOM: Navigation component

Reporter
Yaqoub Aldurayhim
Impact
moderate
References

#CVE-2026-16400: Information disclosure in the DOM: Security component

Reporter
Rintaro Kawasugi
Impact
moderate
References

#CVE-2026-16401: Privilege escalation in the Data Loss Prevention component

Reporter
Brian Carpenter
Impact
moderate
References

#CVE-2026-16402: Integer overflow in the Graphics: ImageLib component

Reporter
Kai Martin
Impact
moderate
References

#CVE-2026-16403: Spoofing issue in the Address Bar component

Reporter
Renwa
Impact
low
References

#CVE-2026-16404: Spoofing issue in Firefox for Android

Reporter
Khiem Tran
Impact
low
References

#CVE-2026-16405: Information disclosure in the Networking: WebSockets component

Reporter
Yaqoub Aldurayhim
Impact
low
References

#CVE-2026-16406: Mitigation bypass in the Networking component

Reporter
Rintaro Kawasugi
Impact
low
References

#CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component

Reporter
bug2own
Impact
low
References

#CVE-2026-16408: Integer overflow in the Audio/Video: Playback component

Reporter
5up3rh3i
Impact
low
References

#CVE-2026-16409: Invalid pointer in the Security: PSM component

Reporter
Artur Cygan
Impact
low
References

#CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component

Reporter
Amy Burnett of OpenAI
Impact
low
References

#CVE-2026-16411: Memory safety bugs fixed in Firefox 153

Reporter
C.M.Chang, Christian Holler, David Parks, Dennis Jackson, Gabriele Svelto, Hafiizh, Henrik Skupin, Jan de Mooij, Jens Stutte, Paul Theriault, Randell Jesup, Rob Wu, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References

#CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153

Reporter
Christian Holler, Frederik Braun, Justin Link, Simon Friedberger, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References

#CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153

Reporter
Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team
Impact
high
Description

Memory safety bugs present in Firefox ESR 115.37, Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.

References