Junglewise Threat Intelligence

CVE-2026-16409: Mozilla Firefox invalid pointer in Security PSM component

CVE-2026-16409 · Severity: info · Published 2026-07-21

Executive brief

Mozilla Firefox was found to have a memory safety issue in its Personal Security Manager (PSM) component, which handles security-related tasks like certificate management. An attacker could potentially exploit this invalid pointer vulnerability to cause the browser to crash or execute unauthorized code. This issue has been resolved in Firefox version 153.

Technical details

An invalid pointer vulnerability was identified in the Security: Personal Security Manager (PSM) component of Mozilla Firefox. The PSM is responsible for cryptographic operations and certificate handling. While specific exploitation details are restricted in the associated Bugzilla report, invalid pointer vulnerabilities typically involve memory corruption that can lead to a denial-of-service (browser crash) or potentially arbitrary code execution within the context of the browser process. The vulnerability is triggered during the processing of security-related data. Users are advised to update to Firefox 153 or later to mitigate this risk.

Affected products

  • Mozilla Firefox < 153

Timeline

  • 2026-07-21: advisory
  • 2026-07-21: patched

References

Related threats