Buffer overflow in Mozilla products - CVE-2026-16360
Published: July 21, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.
How to mitigate CVE-2026-16360
Sources
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-69/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/
- https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2022635%2C2028004%2C2035756%2C2045184%2C2045185%2C2045198%2C2045392%2C2045395%2C2045396%2C2045397%2C2045405%2C2045414%2C2045415%2C2045451%2C2045454%2C2045508%2C2045510%2C2045513%2C2045515%2C2045518%2C2045604%2C2045607%2C2045612%2C2045617%2C2045619%2C2045624%2C2045625%2C2045729%2C2045737%2C2045741%2C2045742%2C2045763%2C2045767%2C2045770%2C2045772%2C2045773%2C2045783%2C2045833%2C2045848%2C2045865%2C2045875%2C2045957%2C2047723%2C2047729%2C2048795%2C2048799%2C2048801%2C2049392%2C2049397%2C2049398%2C2049399%2C2049404%2C2049405%2C2049407%2C2049812%2C2050657%2C2050668%2C2050990%2C2053166%2C2053273%2C2053576%2C2053583%2C2053587