Back to overview

CVE-2026-16356

Description
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Metadata

CVE ID
CVE-2026-16356
State
PUBLISHED
Assigner
mozilla
Reserved
2026-07-20 21:56 UTC
Published
2026-07-21 12:37 UTC
Last updated
2026-07-21 12:37 UTC
Vendor / Product
Mozilla / Firefox
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Mozilla Firefox 115.38 ≤ 115.*, 140.13 ≤ 140.*, 153 ≤ *
Back to overview