Description
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Disability Access APIs component that permits an attacker to escape the sandbox of a web browser or email client and run arbitrary code, compromising confidentiality, integrity, and availability. The weakness falls under CWE‑416 (Use‑After‑Free) and CWE‑772 (Missing Release of Resource on Failure). The description indicates that the sandbox involved is that of the browser or email client; this is inferred because the component is part of Firefox and Thunderbird.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected. All releases prior to Firefox 153, ESR 115.38, ESR 140.13, Thunderbird 153, and Thunderbird 140.13 are vulnerable. These older versions lack the fix and remain at risk.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector involves triggering the use‑after‑free in the Disability Access APIs, potentially through specially crafted content or accessibility data. This inference is drawn from the phrasing of the advisory and the component involved.

Generated by OpenCVE AI on August 3, 2026 at 01:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 153 or newer, or install the latest ESR update (115.38 or 140.13).
  • Upgrade Thunderbird to version 153 or newer, or install the latest ESR update (140.13).
  • If an update cannot be applied immediately, disable the Disability Access APIs feature.

Generated by OpenCVE AI on August 3, 2026 at 01:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Title Sandbox escape due to use-after-free in the Disability Access APIs component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:18.625Z

Reserved: 2026-07-20T21:55:52.955Z

Link: CVE-2026-16352

cve-icon Vulnrichment

Updated: 2026-07-22T15:23:35.605Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T12:37:35Z

Links: CVE-2026-16352 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:15:03Z

Weaknesses
  • CWE-416

    Use After Free

  • CWE-772

    Missing Release of Resource after Effective Lifetime