Junglewise Threat Intelligence

CVE-2026-16358: Mozilla Firefox site isolation issue in WebRender

CVE-2026-16358 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used to access the internet. A security flaw in its graphics rendering component could allow a malicious website to bypass site isolation protections, which are designed to keep data from different websites separate. This could potentially lead to the unauthorized access of sensitive information from other open tabs or websites.

Technical details

A site isolation issue was identified in the Graphics: WebRender component of Mozilla Firefox. The vulnerability stems from a failure to properly enforce process boundaries, which could allow a malicious site to bypass security controls intended to isolate web content. An attacker could exploit this by enticing a user to visit a specially crafted webpage, potentially leading to cross-origin information disclosure. The issue is tracked as Bug 2040119 and has been addressed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 115.38, < 140.13

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched
  • 2026-07-21: advisory

References

Related threats