Junglewise Threat Intelligence

CVE-2026-16368: Mozilla Firefox incorrect boundary conditions in WebAssembly

CVE-2026-16368 · Severity: info · CVSS 8.8 · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a widely used web browser. A vulnerability in its WebAssembly component could allow a malicious website to execute unauthorized code or crash the browser when a user visits a specially crafted page. This could lead to the theft of sensitive information or a complete compromise of the user's computer.

Technical details

An incorrect boundary condition vulnerability exists in the JavaScript: WebAssembly component of Mozilla Firefox. The flaw is rooted in improper validation of array or buffer boundaries during WebAssembly execution. An attacker can exploit this by enticing a user to visit a malicious website containing specially crafted WebAssembly code. Successful exploitation could lead to memory corruption, potentially allowing for arbitrary code execution within the context of the browser process or a denial-of-service (browser crash). The vulnerability is addressed in Firefox 153 and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 140.13

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched
  • 2026-07-21: advisory

References

Related threats