Buffer overflow in Firefox for Android and Mozilla Firefox - CVE-2026-16411
Published: July 22, 2026
Vulnerability identifier: #VU139027
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16411
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to memory corruption in Firefox for Android when processing content. A remote attacker can trigger memory safety bugs to execute arbitrary code.
The advisory states that some of these bugs showed evidence of memory corruption.
Affected software
Firefox for Android
Mozilla Firefox
Mozilla Thunderbird
Mozilla Firefox
Mozilla Thunderbird
How to mitigate CVE-2026-16411
Install security update from vendor's website.
Firefox for Android - update to 153.0
Mozilla Firefox - update to 153.0
Mozilla Thunderbird - update to 153.0
Mozilla Firefox - update to 153.0
Mozilla Thunderbird - update to 153.0