Buffer overflow in Mozilla products - CVE-2026-16412
Published: July 21, 2026
Firefox ESR
Mozilla Firefox
Firefox for Android
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in multiple components when processing crafted content. A remote attacker can trigger memory corruption using crafted content to execute arbitrary code.
Mozilla reported that some of the underlying bugs showed evidence of memory corruption.