Junglewise Threat Intelligence

CVE-2026-16399: Mozilla Firefox site isolation issue in DOM Navigation

CVE-2026-16399 · Severity: info · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

A security vulnerability exists in the Firefox web browser's navigation component. This flaw could allow a malicious website to bypass site isolation protections, which are designed to keep data from different websites separate. If exploited, this could potentially lead to the exposure of sensitive user information across different browsing sessions or tabs.

Technical details

A site isolation vulnerability was identified in the DOM: Navigation component of Mozilla Firefox. The flaw relates to how the browser manages process boundaries during navigation, potentially allowing a malicious site to break out of its isolated sandbox or access data from another origin. This type of vulnerability undermines the security model that ensures web content from different domains is strictly separated in memory. An attacker would typically need to entice a user to visit a specially crafted website to trigger the issue. The vulnerability is resolved in Firefox version 153.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: patched: Fixed in Firefox 153

References

Related threats