Description
We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
Published: 2026-07-14
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Firefox contains a flaw in its navigation component that permits the browser’s site isolation mechanism to be bypassed. The bug may allow an attacker to force a navigation that crosses origin boundaries, thereby granting access to or reading data from another browsing context that should remain isolated. The vulnerability is consistent with CWE‑501, and its current CVSS score of 5.4 indicates moderate severity. Since publicly available exploit code exists but no attacks are reported in the wild, the risk is primarily theoretical.

Affected Systems

Mozilla Firefox builds that have not yet received the patch in version 152.0.6, ESR 115.38, or ESR 140.13, and Mozilla Thunderbird builds that have not yet been updated to version 140.13 may be impacted, but the vendor does not specify an exact affected version range.

Risk and Exploitability

The EPSS score of less than 1% points to a very low probability of exploitation under current conditions, and the vulnerability is not listed in CISA KEV. The likely attack vector is a maliciously crafted web page that triggers navigation across isolation boundaries, potentially exploiting lack of user interaction or unsuspecting user engagement. With no recorded incidents, the threat remains unproven but possible if an attacker can leverage the public exploit code.

Generated by OpenCVE AI on August 3, 2026 at 03:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Firefox update (152.0.6 or newer) to restore the same‑origin policy in the navigation engine.
  • Apply the latest Thunderbird update (140.13 or newer) to restore the same‑origin policy in the navigation engine.
  • If immediate patching is not possible, use a dedicated secure browsing profile, disable extensions that modify navigation or site isolation behavior, and monitor for signs of exploitation.
  • Configure the browser’s security settings through about:config to enforce stricter same‑origin policies or enable relevant flags that limit cross‑origin navigation, providing an additional layer of protection until a patch is applied.

Generated by OpenCVE AI on August 3, 2026 at 03:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Thu, 23 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, and Firefox ESR 140.13. We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.
References

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6. We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, and Firefox ESR 140.13.
Title Site isolation in the DOM: Navigation component Site isolation issue in the DOM: Navigation component
References

Thu, 16 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 14 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6.
Title Site isolation in the DOM: Navigation component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:22.168Z

Reserved: 2026-07-14T12:15:46.894Z

Link: CVE-2026-15719

cve-icon Vulnrichment

Updated: 2026-07-14T13:33:52.400Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Critical

Publid Date: 2026-07-14T12:15:47Z

Links: CVE-2026-15719 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:30:13Z

Weaknesses