Junglewise Threat Intelligence

CVE-2026-16354: Mozilla Firefox information disclosure in ImageLib

CVE-2026-16354 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the image processing library of the Firefox web browser. An attacker could potentially exploit this flaw to access sensitive information that should otherwise be protected. This could lead to the exposure of user data or internal browser information during normal web browsing activities.

Technical details

An information disclosure vulnerability exists in the Graphics: ImageLib component of Mozilla Firefox. The vulnerability is triggered during the processing of images, though the specific root cause (e.g., out-of-bounds read or uninitialized memory) is not publicly detailed in the advisory. A remote attacker could exploit this by enticing a user to visit a specially crafted website, potentially leading to the disclosure of sensitive information from the browser's memory. The issue is addressed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 115.38, < 140.13

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats