Memory Safety Vulnerabilities in Firefox and ESR Versions
CVE-2026-16360
9.8CRITICAL
What is CVE-2026-16360?
Multiple memory safety bugs were identified in Firefox versions ESR 115.37, ESR 140.12, and Firefox 152, leading to potential memory corruption issues. If exploited, these could allow arbitrary code execution. Mozilla addressed these vulnerabilities in Firefox versions 153, ESR 115.38, and ESR 140.13, enhancing security and stability. Users are encouraged to update their browsers promptly to mitigate potential risks.
Affected Version(s)
Firefox 115.38
Firefox 140.13
Firefox 153
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team