Description
Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw permits malicious web content to invoke the DOM navigation component in a way that bypasses the browser’s same‑origin policy, exposing data normally confined to one origin. The flaw is classified as CWE‑346, an information exposure through a same‑origin policy violation. An attacker could thus read cookies, local storage, or other origin‑restricted information from the victim’s browser or email client without requiring operating‑system privileges. The likely attack vector is a crafted web page or email that causes the victim’s software to navigate via the vulnerable component; this inference follows from the description that the issue concerns navigation in the DOM.

Affected Systems

Mozilla Firefox versions older than 153, as well as the ESR builds before 115.38 and 140.13, and Mozilla Thunderbird versions earlier than 153 or ESR builds before 140.13 are impacted; the vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Risk and Exploitability

The CVSS score of 9.8 marks this as a severe vulnerability, while an EPSS score below 1 % indicates a low probability of large‑scale exploitation at present. It is not listed in the CISA KEV catalog, meaning no confirmed public exploits exist. The most probable exploitation path involves a malicious web page or email that triggers the vulnerable navigation component, allowing the attacker to read cross‑origin data. Monitoring and limiting navigation to trusted origins can reduce risk in the meantime.

Generated by OpenCVE AI on August 4, 2026 at 05:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected Mozilla products to the fixed releases (Firefox ≥ 153 or ESR ≥ 115.38/140.13, Thunderbird ≥ 153 or ESR ≥ 140.13).
  • Configure the browser or email client to enforce a stricter same‑origin policy, such as disabling or logging use of the navigation component, or deploying a content‑security‑policy that blocks navigation to disallowed origins.
  • Monitor user traffic for anomalous cross‑origin navigation requests and report any suspicious activity to Mozilla’s security team.

Generated by OpenCVE AI on August 4, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Title Same-origin policy bypass in the DOM: Navigation component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:14.229Z

Reserved: 2026-07-20T21:55:46.392Z

Link: CVE-2026-16349

cve-icon Vulnrichment

Updated: 2026-07-22T15:20:38.855Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T12:37:31Z

Links: CVE-2026-16349 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses