Junglewise Threat Intelligence

CVE-2026-16391: Mozilla Firefox information disclosure in IndexedDB

CVE-2026-16391 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox ESR, Mozilla Firefox. Vendors: Mozilla.

Executive brief

A vulnerability has been identified in Mozilla Firefox's IndexedDB storage component, which is used by the browser to store large amounts of structured data locally. An exploit could allow a malicious website to access information it should not be able to see, potentially compromising user privacy. This issue has been resolved in the latest software updates.

Technical details

An information disclosure vulnerability exists in the IndexedDB component of Mozilla Firefox. The flaw resides within the storage handling logic, potentially allowing for the unauthorized access of data across origin boundaries or the leakage of metadata. An attacker could exploit this by enticing a user to visit a specially crafted website. The vulnerability is classified as moderate impact by Mozilla and has been addressed in Firefox 153 and Firefox ESR 140.13.

Affected products

  • Mozilla Firefox < 153
  • Mozilla Firefox ESR < 140.13

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats