SB2026072302 - Multiple vulnerabilities in Mozilla Thunderbird



SB2026072302 - Multiple vulnerabilities in Mozilla Thunderbird

Published: July 23, 2026

Security Bulletin ID SB2026072302
CSH Severity
High
Patch available
YES
Number of vulnerabilities 61
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 28% Medium 44% Low 28%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 61 vulnerabilities.


1) Improper access control (CVE-ID: CVE-2026-16398)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass site isolation restrictions.

The vulnerability exists due to improper access control in the Graphics component when rendering content. A remote attacker can supply crafted content to bypass site isolation restrictions.


2) Protection mechanism failure (CVE-ID: CVE-2026-16383)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security restriction.

The vulnerability exists due to a mitigation bypass in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security restriction.


3) Use of uninitialized resource (CVE-ID: CVE-2026-16384)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.


4) Use of uninitialized resource (CVE-ID: CVE-2026-16385)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.


5) Use of uninitialized resource (CVE-ID: CVE-2026-16386)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to disclose sensitive information.


6) Protection mechanism failure (CVE-ID: CVE-2026-16387)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to a site isolation issue in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass site isolation.


7) Improper access control (CVE-ID: CVE-2026-16388)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to improper access control in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to escape the sandbox.


8) Integer overflow (CVE-ID: CVE-2026-16389)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Libraries component in NSS when processing input. A remote attacker can supply crafted input to cause a denial of service.

The advisory also reports incorrect boundary conditions in the same component.


9) Protection mechanism failure (CVE-ID: CVE-2026-16390)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security restriction.

The vulnerability exists due to a mitigation bypass in the Enterprise Policies component when applying enterprise policies. A remote attacker can trigger crafted policy conditions to bypass a security restriction.


10) Information disclosure (CVE-ID: CVE-2026-16391)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an information disclosure flaw in the Storage: IndexedDB component when handling stored web data. A remote attacker can trigger crafted storage interactions to disclose sensitive information.


11) Incorrect calculation (CVE-ID: CVE-2026-16392)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when compiling script code. A remote attacker can supply crafted script code to execute arbitrary code.


12) Buffer overflow (CVE-ID: CVE-2026-16393)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to cause a denial of service.


13) Input validation error (CVE-ID: CVE-2026-16359)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: GMP component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.


14) Protection mechanism failure (CVE-ID: CVE-2026-16394)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Security component when handling security checks. A remote attacker can trigger crafted behavior to bypass a security mitigation.


15) Integer overflow (CVE-ID: CVE-2026-16395)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Audio/Video component when processing audio or video content. A remote attacker can supply crafted media content to cause a denial of service.


16) Improper privilege management (CVE-ID: CVE-2026-16396)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improper access control in WebExtensions when using extension functionality. A remote user can abuse extension functionality to escalate privileges.

Exploitation requires the use of WebExtensions.


17) Protection mechanism failure (CVE-ID: CVE-2026-16382)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Service Workers component when handling service worker operations. A remote attacker can trigger crafted service worker behavior to bypass a security mitigation.


18) Improper access control (CVE-ID: CVE-2026-16399)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass site isolation restrictions.

The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to bypass site isolation restrictions.


19) Information disclosure (CVE-ID: CVE-2026-16400)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to information exposure in the DOM: Security component when handling security checks. A remote attacker can trigger crafted behavior to disclose sensitive information.


20) Improper privilege management (CVE-ID: CVE-2026-16401)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the Data Loss Prevention component when handling data loss prevention functionality. A remote attacker can trigger crafted behavior to escalate privileges.


21) Integer overflow (CVE-ID: CVE-2026-16402)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Graphics: ImageLib component when processing image content. A remote attacker can supply crafted image content to cause a denial of service.


22) Spoofing attack (CVE-ID: CVE-2026-16403)

CWE-ID: CWE-451 - User Interface (UI) Misrepresentation of Critical Information (Clickjacking, spoofing)

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to spoof trusted content.

The vulnerability exists due to improper user interface control in the Address Bar component when displaying address information. A remote attacker can present crafted address information to spoof trusted content.


23) Information disclosure (CVE-ID: CVE-2026-16405)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an information disclosure flaw in the Networking: WebSockets component when handling WebSocket connections. A remote attacker can trigger crafted WebSocket behavior to disclose sensitive information.


24) Protection mechanism failure (CVE-ID: CVE-2026-16406)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.


25) Protection mechanism failure (CVE-ID: CVE-2026-16407)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Service Workers component when handling service worker operations. A remote attacker can trigger crafted service worker behavior to bypass a security mitigation.


26) Integer overflow (CVE-ID: CVE-2026-16408)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to integer overflow in the Audio/Video: Playback component when processing audio or video content. A remote attacker can supply crafted media content to cause a denial of service.


27) NULL pointer dereference (CVE-ID: CVE-2026-16409)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to invalid pointer dereference in the Security: PSM component when handling security operations. A remote attacker can trigger crafted behavior to cause a denial of service.


28) Incorrect calculation (CVE-ID: CVE-2026-16410)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when compiling script code. A remote attacker can supply crafted script code to cause a denial of service.


29) Buffer overflow (CVE-ID: CVE-2026-16411)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in Firefox for Android when processing content. A remote attacker can trigger memory safety bugs to execute arbitrary code.

The advisory states that some of these bugs showed evidence of memory corruption.


30) Buffer overflow (CVE-ID: CVE-2026-16412)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple components when processing crafted content. A remote attacker can trigger memory corruption using crafted content to execute arbitrary code.

Mozilla reported that some of the underlying bugs showed evidence of memory corruption.


31) Buffer overflow (CVE-ID: CVE-2026-16360)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.

Some of the underlying bugs showed evidence of memory corruption.


32) Incorrect calculation (CVE-ID: CVE-2026-16355)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the JavaScript Engine: JIT component when executing script content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.


33) Improper access control (CVE-ID: CVE-2026-16349)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass the same-origin policy.


34) Input validation error (CVE-ID: CVE-2026-16350)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: cubeb component when processing media content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.


35) Use-after-free (CVE-ID: CVE-2026-16362)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to use-after-free in the WebRTC: Audio/Video component when processing real-time audio or video content. A remote attacker can trigger the flaw using crafted real-time media interactions to execute arbitrary code.


36) Use-after-free (CVE-ID: CVE-2026-16351)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the DOM: Navigation component when handling navigation. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.


37) Use-after-free (CVE-ID: CVE-2026-16352)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.


38) Incorrect calculation (CVE-ID: CVE-2026-16363)

CWE-ID: CWE-682 - Incorrect Calculation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to JIT miscompilation in the JavaScript: WebAssembly component when compiling and executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.


39) Buffer overflow (CVE-ID: CVE-2026-16364)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Audio/Video: Playback component when processing audio or video content. A remote attacker can supply crafted media content to execute arbitrary code.


40) Improper privilege management (CVE-ID: CVE-2026-16365)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Workers component when handling worker operations. A remote attacker can trigger crafted worker behavior to escalate privileges.


41) Improper privilege management (CVE-ID: CVE-2026-16366)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.


42) NULL pointer dereference (CVE-ID: CVE-2026-16353)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to an invalid pointer in the DOM: Bindings (WebIDL) component when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.


43) Information disclosure (CVE-ID: CVE-2026-16354)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in the Graphics: ImageLib component when processing image content. A remote attacker can convince the victim to visit a specially crafted website or URL to disclose sensitive information.


44) NULL pointer dereference (CVE-ID: CVE-2026-16367)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to invalid pointer dereference in the Disability Access APIs component when interacting with accessibility features. A remote attacker can trigger crafted interaction with accessibility features to escape the sandbox.


45) Out-of-bounds read (CVE-ID: CVE-2026-16368)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to incorrect boundary conditions in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to cause a denial of service.


46) Integer overflow (CVE-ID: CVE-2026-16369)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to integer overflow in the JavaScript: WebAssembly component when compiling or executing WebAssembly content. A remote attacker can supply crafted WebAssembly content to execute arbitrary code.


47) Off-by-one (CVE-ID: CVE-2026-14899)

CWE-ID: CWE-193 - Off-by-one Error

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an off-by-one error within the MIME header parser. A remote attacker can trick the victim into opening a specially crafted email and read contents of memory on the system or crash the application.


48) Use-after-free (CVE-ID: CVE-2026-16356)

CWE-ID: CWE-416 - Use After Free

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escape the sandbox.

The vulnerability exists due to use-after-free in the Disability Access APIs component when interacting with accessibility functionality. A remote attacker can convince the victim to visit a specially crafted website or URL to escape the sandbox.


49) Input validation error (CVE-ID: CVE-2026-16357)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to incorrect boundary conditions in the Graphics component when processing rendered content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.


50) Protection mechanism failure (CVE-ID: CVE-2026-16370)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the DOM: Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.


51) Improper privilege management (CVE-ID: CVE-2026-16371)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Navigation component when handling navigation operations. A remote attacker can trigger crafted navigation behavior to escalate privileges.


52) Improper privilege management (CVE-ID: CVE-2026-16372)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.


53) Information disclosure (CVE-ID: CVE-2026-16374)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to an information disclosure flaw in the Framework component in DevTools when using developer tools functionality. A remote attacker can trigger the flaw through crafted developer tools interactions to disclose sensitive information.


54) Protection mechanism failure (CVE-ID: CVE-2026-16375)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to a site isolation issue in the Networking: HTTP component when handling HTTP traffic. A remote attacker can trigger crafted HTTP behavior to bypass site isolation.


55) Input validation error (CVE-ID: CVE-2026-16376)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input handling in the Graphics: WebGPU component when processing WebGPU operations. A remote attacker can trigger crafted WebGPU operations to cause a denial of service.


56) Protection mechanism failure (CVE-ID: CVE-2026-16377)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security restriction.

The vulnerability exists due to a mitigation bypass in the PDF Viewer component when rendering PDF content. A remote attacker can supply crafted PDF content to bypass a security restriction.


57) Input validation error (CVE-ID: CVE-2026-16378)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to improper input handling in the DOM: Copy & Paste and Drag & Drop component when handling copy, paste, and drag-and-drop operations. A remote attacker can trigger crafted user interface interactions to perform unauthorized actions.


58) Improper privilege management (CVE-ID: CVE-2026-16379)

CWE-ID: CWE-269 - Improper Privilege Management

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper access control in the DOM: Content Processes component when handling content processes. A remote attacker can trigger crafted content process behavior to escalate privileges.


59) Improper access control (CVE-ID: CVE-2026-16358)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass site isolation.

The vulnerability exists due to a site isolation issue in the Graphics: WebRender component when rendering content. A remote attacker can convince the victim to visit a specially crafted website or URL to bypass site isolation.


60) Protection mechanism failure (CVE-ID: CVE-2026-16380)

CWE-ID: CWE-693 - Protection Mechanism Failure

CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to bypass a security mitigation.

The vulnerability exists due to improper access control in the Networking component when handling network operations. A remote attacker can trigger crafted network behavior to bypass a security mitigation.


61) Improper access control (CVE-ID: CVE-2026-16381)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber


The vulnerability allows a remote attacker to bypass the same-origin policy.

The vulnerability exists due to improper access control in the Networking: DNS component when resolving DNS requests. A remote attacker can trigger crafted DNS behavior to bypass the same-origin policy.


Remediation

Install update from vendor's website.