Memory Safety Vulnerabilities in Firefox and ESR Versions
CVE-2026-16360

9.8CRITICAL

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
21 July 2026

What is CVE-2026-16360?

Multiple memory safety bugs were identified in Firefox versions ESR 115.37, ESR 140.12, and Firefox 152, leading to potential memory corruption issues. If exploited, these could allow arbitrary code execution. Mozilla addressed these vulnerabilities in Firefox versions 153, ESR 115.38, and ESR 140.13, enhancing security and stability. Users are encouraged to update their browsers promptly to mitigate potential risks.

Affected Version(s)

Firefox 115.38

Firefox 140.13

Firefox 153

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew McCreight, Jan de Mooij, Tom Ritter, Vincent Hilla and the Mozilla Fuzzing Team
.