NULL pointer dereference in Mozilla products - CVE-2026-16353
Published: July 21, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.
The vulnerability exists due to an invalid pointer in the DOM: Bindings (WebIDL) component when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to cause a denial of service or execute arbitrary code.