Junglewise Threat Intelligence

CVE-2026-16389: Mozilla NSS integer overflow in Libraries component

CVE-2026-16389 · Severity: info · CVSS 6.5 · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability exists in the Network Security Services (NSS) library, which is a set of libraries designed to support cross-platform development of security-enabled client and server applications. In the context of the Firefox web browser, this flaw could potentially allow an attacker to cause a crash or execute unauthorized code by exploiting how the software handles memory boundaries. This could lead to a compromise of user data or browser stability.

Technical details

An integer overflow and incorrect boundary conditions vulnerability exists within the Libraries component of Mozilla's Network Security Services (NSS). The flaw is triggered when the library improperly calculates memory buffer sizes or fails to validate bounds during data processing. An attacker could potentially exploit this via a specially crafted network response or web content to cause a buffer overflow. This could lead to a denial-of-service (browser crash) or potentially arbitrary code execution within the context of the application using the affected NSS version. The issue is resolved in Firefox 153 and the corresponding updated versions of the NSS library.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Network Security Services (NSS) Fixed in Firefox 153

Timeline

  • 2026-07-21: advisory: Mozilla Foundation Security Advisory MFSA2026-68 published
  • 2026-07-21: patched: Fixed in Firefox 153

References

Related threats