SB2026072201 - Multiple vulnerabilities in Mozilla Firefox
Published: July 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 64 vulnerabilities.
1) Protection mechanism failure (CVE-ID: CVE-2026-16394)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Security component when handling security checks. A remote attacker can trigger crafted behavior to bypass a security mitigation.
2) NULL pointer dereference (CVE-ID: CVE-2026-16367)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to invalid pointer dereference in the Disability Access APIs component when interacting with accessibility features. A remote attacker can trigger crafted interaction with accessibility features to escape the sandbox.
3) Protection mechanism failure (CVE-ID: CVE-2026-16370)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.
4) Improper privilege management (CVE-ID: CVE-2026-16372)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.
5) Information disclosure (CVE-ID: CVE-2026-16373)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information exposure in the Privacy component when handling privacy-related functionality. A remote attacker can trigger crafted interactions to disclose sensitive information.
This issue is specific to Firefox for Android.
6) Input validation error (CVE-ID: CVE-2026-16376)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input handling in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to cause a denial of service.
7) Input validation error (CVE-ID: CVE-2026-16378)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform unauthorized actions.
The vulnerability exists due to improper input handling in the DOM: Copy & Paste and Drag & Drop component when handling copy, paste, and drag-and-drop operations. A remote attacker can trigger crafted user interface interactions to perform unauthorized actions.
8) Protection mechanism failure (CVE-ID: CVE-2026-16380)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.
9) Protection mechanism failure (CVE-ID: CVE-2026-16382)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Service Workers component when handling service worker operations. A remote attacker can trigger crafted service worker behavior to bypass a security mitigation.
10) Use of uninitialized resource (CVE-ID: CVE-2026-16384)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.
11) Use of uninitialized resource (CVE-ID: CVE-2026-16385)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.
12) Use of uninitialized resource (CVE-ID: CVE-2026-16386)
CWE-ID: CWE-908 - Use of Uninitialized Resource
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.
13) Improper access control (CVE-ID: CVE-2026-16388)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to improper access control in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to escape the sandbox.
14) Integer overflow (CVE-ID: CVE-2026-16389)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Libraries component in NSS when processing input. A remote attacker can supply crafted input to cause a denial of service.
The advisory also reports incorrect boundary conditions in the same component.
15) Incorrect calculation (CVE-ID: CVE-2026-16392)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when compiling script code. A remote attacker can supply crafted script code to execute arbitrary code.
16) Buffer overflow (CVE-ID: CVE-2026-16393)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect boundary conditions in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to cause a denial of service.
17) Improper privilege management (CVE-ID: CVE-2026-16366)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.
18) Integer overflow (CVE-ID: CVE-2026-16395)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Audio/Video component when processing audio or video content. A remote attacker can supply crafted media content to cause a denial of service.
19) Improper Restriction of Rendered UI Layers or Frames (CVE-ID: CVE-2026-16397)
CWE-ID: CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform clickjacking attacks.
The vulnerability exists due to improper user interface control in the WebExtensions component when rendering extension user interface elements. A remote attacker can present crafted interface elements to perform clickjacking attacks.
This issue is specific to Firefox for Android.
20) Improper access control (CVE-ID: CVE-2026-16398)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can supply crafted content to bypass site isolation restrictions.
21) Improper access control (CVE-ID: CVE-2026-16399)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation restrictions.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to bypass site isolation restrictions.
22) Information disclosure (CVE-ID: CVE-2026-16400)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information exposure in the DOM: Security component when handling security checks. A remote attacker can trigger crafted behavior to disclose sensitive information.
23) Improper privilege management (CVE-ID: CVE-2026-16401)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the Data Loss Prevention component when handling data loss prevention functionality. A remote attacker can trigger crafted behavior to escalate privileges.
24) Integer overflow (CVE-ID: CVE-2026-16402)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Graphics: ImageLib component when processing image content. A remote attacker can supply crafted image content to cause a denial of service.
25) Spoofing attack (CVE-ID: CVE-2026-16403)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof trusted content.
The vulnerability exists due to improper user interface control in the Address Bar component when displaying address information. A remote attacker can present crafted address information to spoof trusted content.
26) Spoofing attack (CVE-ID: CVE-2026-16404)
CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to spoof trusted content.
The vulnerability exists due to improper user interface control in Firefox for Android when displaying content. A remote attacker can present crafted content to spoof trusted content.
This issue is specific to Firefox for Android.
27) Protection mechanism failure (CVE-ID: CVE-2026-16406)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.
28) Protection mechanism failure (CVE-ID: CVE-2026-16407)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security mitigation.
The vulnerability exists due to improper access control in the DOM: Service Workers component when handling service worker operations. A remote attacker can trigger crafted service worker behavior to bypass a security mitigation.
29) Integer overflow (CVE-ID: CVE-2026-16408)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Audio/Video: Playback component when processing audio or video content. A remote attacker can supply crafted media content to cause a denial of service.
30) NULL pointer dereference (CVE-ID: CVE-2026-16409)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to invalid pointer dereference in the Security: PSM component when handling security operations. A remote attacker can trigger crafted behavior to cause a denial of service.
31) Incorrect calculation (CVE-ID: CVE-2026-16410)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when compiling script code. A remote attacker can supply crafted script code to cause a denial of service.
32) Buffer overflow (CVE-ID: CVE-2026-16411)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in Firefox for Android when processing content. A remote attacker can trigger memory safety bugs to execute arbitrary code.
The advisory states that some of these bugs showed evidence of memory corruption.
33) Integer overflow (CVE-ID: CVE-2026-16369)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to integer overflow in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.
34) Input validation error (CVE-ID: CVE-2026-16350)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: cubeb component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
35) Use-after-free (CVE-ID: CVE-2026-16351)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
36) Use-after-free (CVE-ID: CVE-2026-16352)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
37) NULL pointer dereference (CVE-ID: CVE-2026-16353)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to an invalid pointer in the DOM: Bindings (WebIDL) component when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
38) Information disclosure (CVE-ID: CVE-2026-16354)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the Graphics: ImageLib component when processing image content. A remote attacker can convince the victim to visit a specially crafted website or URL to disclose sensitive information.
39) Incorrect calculation (CVE-ID: CVE-2026-16355)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing script content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
40) Use-after-free (CVE-ID: CVE-2026-16356)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escape the sandbox.
The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.
41) Input validation error (CVE-ID: CVE-2026-16357)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing rendered content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
42) Improper access control (CVE-ID: CVE-2026-16358)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Graphics: WebRender component when rendering content. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass site isolation.
43) Input validation error (CVE-ID: CVE-2026-16359)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: GMP component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.
44) Buffer overflow (CVE-ID: CVE-2026-16360)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.
45) Buffer overflow (CVE-ID: CVE-2026-16361)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.
46) Use-after-free (CVE-ID: CVE-2026-16362)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to use-after-free in the WebRTC: Audio/Video component when processing real-time audio or video content. A remote attacker can trigger the flaw using crafted real-time media interactions to execute arbitrary code.
47) Incorrect calculation (CVE-ID: CVE-2026-16363)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when compiling and executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.
48) Out-of-bounds read (CVE-ID: CVE-2026-16368)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incorrect boundary conditions in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to cause a denial of service.
49) Improper access control (CVE-ID: CVE-2026-16349)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass the same-origin policy.
50) Improper privilege management (CVE-ID: CVE-2026-16371)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.
51) Information disclosure (CVE-ID: CVE-2026-16374)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Framework component in DevTools when using developer tools functionality. A remote attacker can trigger the flaw through crafted developer tools interactions to disclose sensitive information.
52) Protection mechanism failure (CVE-ID: CVE-2026-16375)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Networking: HTTP component when handling HTTP traffic. A remote attacker can trigger crafted HTTP behavior to bypass site isolation.
53) Protection mechanism failure (CVE-ID: CVE-2026-16377)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the PDF Viewer component when rendering PDF content. A remote attacker can supply crafted PDF content to bypass a security restriction.
54) Improper privilege management (CVE-ID: CVE-2026-16379)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.
55) Improper access control (CVE-ID: CVE-2026-16381)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass the same-origin policy.
The vulnerability exists due to improper access control in the Networking: DNS component when resolving DNS requests. A remote attacker can trigger crafted DNS behavior to bypass the same-origin policy.
56) Protection mechanism failure (CVE-ID: CVE-2026-16383)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security restriction.
57) Protection mechanism failure (CVE-ID: CVE-2026-16387)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass site isolation.
The vulnerability exists due to a site isolation issue in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass site isolation.
58) Protection mechanism failure (CVE-ID: CVE-2026-16390)
CWE-ID: CWE-693 - Protection Mechanism Failure
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass a security restriction.
The vulnerability exists due to a mitigation bypass in the Enterprise Policies component when applying enterprise policies. A remote attacker can trigger crafted policy conditions to bypass a security restriction.
59) Information disclosure (CVE-ID: CVE-2026-16391)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Storage: IndexedDB component when handling stored web data. A remote attacker can trigger crafted storage interactions to disclose sensitive information.
60) Improper privilege management (CVE-ID: CVE-2026-16396)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in WebExtensions when using extension functionality. A remote user can abuse extension functionality to escalate privileges.
Exploitation requires the use of WebExtensions.
61) Information disclosure (CVE-ID: CVE-2026-16405)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an information disclosure flaw in the Networking: WebSockets component when handling WebSocket connections. A remote attacker can trigger crafted WebSocket behavior to disclose sensitive information.
62) Buffer overflow (CVE-ID: CVE-2026-16412)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing crafted content. A remote attacker can trigger memory corruption using crafted content to execute arbitrary code.
Mozilla reported that some of the underlying bugs showed evidence of memory corruption.
63) Buffer overflow (CVE-ID: CVE-2026-16364)
CWE-ID: CWE-119 - Memory corruption
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when processing audio or video content. A remote attacker can supply crafted media content to execute arbitrary code.
64) Improper privilege management (CVE-ID: CVE-2026-16365)
CWE-ID: CWE-269 - Improper Privilege Management
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper access control in the DOM: Workers component when handling worker operations. A remote attacker can trigger crafted worker behavior to escalate privileges.
Remediation
Install update from vendor's website.
References
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2046748
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050627
- https://bugzilla.mozilla.org/show_bug.cgi?id=1996495
- https://bugzilla.mozilla.org/show_bug.cgi?id=2013800
- https://bugzilla.mozilla.org/show_bug.cgi?id=2021964
- https://bugzilla.mozilla.org/show_bug.cgi?id=2035733
- https://bugzilla.mozilla.org/show_bug.cgi?id=2038868
- https://bugzilla.mozilla.org/show_bug.cgi?id=2040386
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041864
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041911
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041912
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041916
- https://bugzilla.mozilla.org/show_bug.cgi?id=2043845
- https://bugzilla.mozilla.org/show_bug.cgi?id=2043887
- https://bugzilla.mozilla.org/show_bug.cgi?id=2044606
- https://bugzilla.mozilla.org/show_bug.cgi?id=2045410
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049181
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047221
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047608
- https://bugzilla.mozilla.org/show_bug.cgi?id=2048345
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049981
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050430
- https://bugzilla.mozilla.org/show_bug.cgi?id=2052565
- https://bugzilla.mozilla.org/show_bug.cgi?id=2052703
- https://bugzilla.mozilla.org/show_bug.cgi?id=1972244
- https://bugzilla.mozilla.org/show_bug.cgi?id=2020253
- https://bugzilla.mozilla.org/show_bug.cgi?id=2040382
- https://bugzilla.mozilla.org/show_bug.cgi?id=2044063
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050477
- https://bugzilla.mozilla.org/show_bug.cgi?id=2052134
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053680
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2048936%2C2049804
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051854
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/
- https://bugzilla.mozilla.org/show_bug.cgi?id=2042033
- https://bugzilla.mozilla.org/show_bug.cgi?id=2045468
- https://bugzilla.mozilla.org/show_bug.cgi?id=2046416
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049523
- https://bugzilla.mozilla.org/show_bug.cgi?id=2050626
- https://bugzilla.mozilla.org/show_bug.cgi?id=2052207
- https://bugzilla.mozilla.org/show_bug.cgi?id=2052562
- https://bugzilla.mozilla.org/show_bug.cgi?id=2053326
- https://bugzilla.mozilla.org/show_bug.cgi?id=2040119
- https://bugzilla.mozilla.org/show_bug.cgi?id=2045424
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022635%2C2028004%2C2035756%2C2045184%2C2045185%2C2045198%2C2045392%2C2045395%2C2045396%2C2045397%2C2045405%2C2045414%2C2045415%2C2045451%2C2045454%2C2045508%2C2045510%2C2045513%2C2045515%2C2045518%2C2045604%2C2045607%2C2045612%2C2045617%2C2045619%2C2045624%2C2045625%2C2045729%2C2045737%2C2045741%2C2045742%2C2045763%2C2045767%2C2045770%2C2045772%2C2045773%2C2045783%2C2045833%2C2045848%2C2045865%2C2045875%2C2045957%2C2047723%2C2047729%2C2048795%2C2048799%2C2048801%2C2049392%2C2049397%2C2049398%2C2049399%2C2049404%2C2049405%2C2049407%2C2049812%2C2050657%2C2050668%2C2050990%2C2053166%2C2053273%2C2053576%2C2053583%2C2053587
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2029734%2C2036518
- https://bugzilla.mozilla.org/show_bug.cgi?id=2043188
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047689
- https://bugzilla.mozilla.org/show_bug.cgi?id=2051015
- https://bugzilla.mozilla.org/show_bug.cgi?id=2034682
- https://bugzilla.mozilla.org/show_bug.cgi?id=2008369
- https://bugzilla.mozilla.org/show_bug.cgi?id=2027519
- https://bugzilla.mozilla.org/show_bug.cgi?id=2032140
- https://bugzilla.mozilla.org/show_bug.cgi?id=2037770
- https://bugzilla.mozilla.org/show_bug.cgi?id=2039452
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041001
- https://bugzilla.mozilla.org/show_bug.cgi?id=2041902
- https://bugzilla.mozilla.org/show_bug.cgi?id=2043200
- https://bugzilla.mozilla.org/show_bug.cgi?id=2044527
- https://bugzilla.mozilla.org/show_bug.cgi?id=2044536
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047240
- https://bugzilla.mozilla.org/show_bug.cgi?id=2036591
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2043035%2C2045057%2C2045187%2C2045402%2C2045417%2C2045482%2C2045611%2C2045618%2C2045756%2C2046917%2C2047718
- https://bugzilla.mozilla.org/show_bug.cgi?id=2047802
- https://bugzilla.mozilla.org/show_bug.cgi?id=2049149