Junglewise Threat Intelligence

CVE-2026-16398: Mozilla Firefox site isolation issue in Graphics component

CVE-2026-16398 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used for accessing the internet. A vulnerability in the browser's graphics component could allow a malicious website to bypass site isolation protections, which are designed to keep data from different websites separate. If exploited, this could potentially allow one website to access sensitive information from another site open in the same browser session.

Technical details

A site isolation issue was identified in the Graphics component of Mozilla Firefox. The vulnerability allows for a potential breakdown of the security boundaries that separate content from different origins. An attacker could leverage this flaw via a specially crafted web page to bypass site isolation protections. The issue is tracked as Bug 2048345 within Mozilla's internal tracker. The vulnerability is resolved in Firefox version 153.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: disclosed
  • 2026-07-21: patched

References

Related threats