Executive brief
A security vulnerability has been identified in the networking component of the Firefox web browser. This issue relates to site isolation, a security feature designed to keep data from different websites separate. If exploited, this could potentially allow a malicious website to bypass these boundaries and access information from other open sites or sessions, compromising user privacy and data security.
Technical details
A site isolation vulnerability was identified in the Networking component of Mozilla Firefox. The flaw, tracked as CVE-2026-16387, involves a failure to properly enforce origin boundaries within the networking stack. An attacker could potentially leverage this to bypass the Same-Origin Policy (SOP) or other site isolation mitigations. The vulnerability is reachable via network-based vectors when a user visits a malicious site. Mozilla has addressed this issue in Firefox 153 and Firefox ESR 140.13. Specific technical details regarding the root cause are currently restricted in the associated Bugzilla report (Bug 2043200).
Affected products
- Mozilla Firefox < 153
- Mozilla Firefox ESR < 140.13
Timeline
- 2026-07-21: advisory: Mozilla Foundation Security Advisory 2026-68 and 2026-70 published.
- 2026-07-21: patched: Fixed in Firefox 153 and Firefox ESR 140.13.