Junglewise Threat Intelligence

CVE-2026-16375: Mozilla Firefox site isolation issue in Networking: HTTP component

CVE-2026-16375 · Severity: info · CVSS 6.5 · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security flaw in the Firefox web browser's HTTP networking component could allow a website to bypass site isolation protections. Site isolation is a critical security feature that keeps data from different websites separate to prevent one site from stealing information from another. If exploited, a malicious website might be able to access sensitive data belonging to other sites the user has open.

Technical details

A site isolation vulnerability exists in the Networking: HTTP component of Mozilla Firefox. The flaw relates to how the browser handles process separation for HTTP traffic, potentially allowing a malicious site to bypass the security boundaries intended to isolate web content. An attacker could leverage this to access sensitive information from other origins, such as cookies or session data, violating the Same-Origin Policy. The vulnerability is addressed in Firefox 153 and Firefox ESR 140.13. While specific root cause details are restricted in the associated Bugzilla report (Bug 2032140), Mozilla classifies the impact as 'moderate'.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 140.13

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched
  • 2026-07-21: advisory

References

Related threats