Junglewise Threat Intelligence

CVE-2026-16351: Mozilla Firefox sandbox escape in DOM Navigation component

CVE-2026-16351 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability has been identified in the Mozilla Firefox web browser's navigation component. This flaw could allow a malicious website to bypass the browser's security 'sandbox,' which is designed to keep web content isolated from the rest of the computer. If successfully exploited, an attacker could potentially gain unauthorized access to the underlying operating system or user data.

Technical details

A use-after-free vulnerability exists in the DOM: Navigation component of Mozilla Firefox. The flaw occurs when the browser incorrectly manages memory during navigation events, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a specially crafted webpage, a remote attacker could exploit this condition to achieve a sandbox escape. This vulnerability affects Firefox versions prior to 153, Firefox ESR versions prior to 115.38, and Firefox ESR versions prior to 140.13.

Affected products

  • Mozilla Firefox Before 153
  • Mozilla Firefox ESR Before 115.38, Before 140.13

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats