Description
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free in the Disability Access APIs component that allows an attacker to escape the sandbox and execute code outside the browser or email client. This can compromise confidentiality, integrity, or availability of the host system, and the weakness corresponds to CWE‑416 and CWE‑693.

Affected Systems

Mozilla Firefox releases earlier than version 153, including any ESR releases older than 115.38 and 140.13, and Mozilla Thunderbird releases earlier than version 153, including any ESR releases older than 140.13, all of which expose the accessibility feature.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity, while the EPSS score of <1% shows a low probability of exploitation yet still high risk because the vulnerability enables full sandbox escape. Based on the description, it is inferred that a maliciously crafted web page or email containing specially constructed accessibility elements could trigger the use‑after‑free, thereby allowing a sandbox escape. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to deliver such content to a user who has the Accessibility feature enabled, and the attack would occur locally in the user's environment.

Generated by OpenCVE AI on August 4, 2026 at 05:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Firefox or Thunderbird release that includes the patch (Firefox 153 or ESR 140.13 or newer, Thunderbird 153 or ESR 140.13 or newer).
  • Disable the Accessibility feature as a temporary workaround by setting accessibility.forceEnabled to false in about:config.
  • Monitor browser and system event logs for unusual accessibility API activity that could indicate attempts to exploit a sandbox escape.

Generated by OpenCVE AI on August 4, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416
CWE-693
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Title Sandbox escape due to use-after-free in the Disability Access APIs component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:30.529Z

Reserved: 2026-07-20T21:56:01.537Z

Link: CVE-2026-16356

cve-icon Vulnrichment

Updated: 2026-07-22T15:39:41.586Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:04.100

Modified: 2026-07-24T15:28:09.227

Link: CVE-2026-16356

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-21T12:37:44Z

Links: CVE-2026-16356 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses