Junglewise Threat Intelligence

CVE-2026-16371: Mozilla Firefox privilege escalation in DOM Navigation component

CVE-2026-16371 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A privilege escalation vulnerability exists in the navigation component of the Firefox web browser. This component manages how the browser moves between different web pages and handles document objects. If exploited, this flaw could allow a malicious website to gain higher-level permissions than intended, potentially compromising user data or browser security settings.

Technical details

A privilege escalation vulnerability was identified in the DOM: Navigation component of Mozilla Firefox. The flaw resides in the logic governing document navigation and object model interactions. While specific root cause details are restricted in the associated bug report (Bug 2008369), the vulnerability allows for an escalation of privilege within the browser's execution context. An attacker could potentially exploit this by enticing a user to visit a specially crafted website. The issue is resolved in Firefox 153 and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 140.13

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched
  • 2026-07-21: advisory

References

Related threats