Junglewise Threat Intelligence

CVE-2026-16400: Mozilla Firefox information disclosure in DOM Security component

CVE-2026-16400 · Severity: info · CVSS 5.3 · Published 2026-07-21

Technologies: Mozilla Firefox. Vendors: Mozilla.

Executive brief

Mozilla Firefox is a popular web browser used to access the internet. A security flaw in the browser's internal security component could allow sensitive information to be disclosed to unauthorized parties. This could potentially compromise user privacy or expose data from visited websites. Users should update to version 153 or later to resolve this issue.

Technical details

An information disclosure vulnerability was identified in the DOM: Security component of Mozilla Firefox. The flaw allows for the unintended exposure of data, though specific root cause details (such as the exact nature of the leak) are restricted in the associated Bugzilla report. The vulnerability is reachable via the network through web content. An attacker could potentially leverage this to bypass certain security boundaries and access sensitive information within the browser context. The issue is resolved in Firefox version 153.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: advisory: Mozilla Foundation Security Advisory 2026-68 published.
  • 2026-07-21: patched: Fixed in Firefox 153.

References

Related threats