Buffer overflow in Mozilla products - CVE-2026-16361
Published: July 21, 2026
Mozilla Firefox
Firefox ESR
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing web content. A remote attacker can convince the victim to visit a specially crafted website or URL to execute arbitrary code.
Some of the underlying bugs showed evidence of memory corruption.