Information Disclosure in Firefox IndexedDB Component
CVE-2026-16391

Currently unrated

Key Information:

Vendor

Mozilla

Status
Vendor
CVE Published:
21 July 2026

What is CVE-2026-16391?

A vulnerability exists in the IndexedDB component of Firefox that may lead to information disclosure. This flaw allows an attacker to gain access to sensitive data stored in the IndexedDB database, potentially compromising user privacy and security. Mozilla addressed this vulnerability in Firefox version 153 and Firefox ESR 140.13. Users are advised to upgrade their software to mitigate this risk and ensure the integrity of their stored information.

Affected Version(s)

Firefox 140.13

Firefox 153

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tomoya Nakanishi
.