Buffer overflow in Firefox for Android and Mozilla Firefox - CVE-2026-16411

 

Buffer overflow in Firefox for Android and Mozilla Firefox - CVE-2026-16411

Published: July 22, 2026


Vulnerability identifier: #VU139027
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16411
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to memory corruption in Firefox for Android when processing content. A remote attacker can trigger memory safety bugs to execute arbitrary code.

The advisory states that some of these bugs showed evidence of memory corruption.


Affected software

Firefox for Android
Mozilla Firefox
Mozilla Thunderbird

How to mitigate CVE-2026-16411

Install security update from vendor's website.

Firefox for Android - update to 153.0
Mozilla Firefox - update to 153.0
Mozilla Thunderbird - update to 153.0

External References

Related Security Bulletins