Junglewise Threat Intelligence

CVE-2026-16360: Mozilla Firefox memory safety bugs

CVE-2026-16360 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla has released security updates to address multiple memory safety vulnerabilities in the Firefox web browser. If exploited, these flaws could allow an attacker to crash the browser or potentially execute malicious code on a user's computer. This typically occurs if a user visits a specially crafted malicious website.

Technical details

This advisory covers a collection of memory safety bugs (CVE-2026-16360) identified through internal testing and fuzzing. The vulnerabilities manifest as memory corruption issues within the browser engine. An attacker could potentially exploit these flaws by enticing a user to process malicious web content, leading to arbitrary code execution within the context of the browser process. The issues were identified by Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla, and the Mozilla Fuzzing Team. Patches are available in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox 152
  • Mozilla Firefox ESR 115.37, 140.12

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats