Description
Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw permits a malicious web page to break the site isolation barrier enforced by the WebRender graphics engine, enabling the attacker to read rendered output from a page that it does not control. The vulnerability is identified as CWE-346 and CWE-368. Because the flaw allows information leakage rather than arbitrary code execution, the primary consequence is a breach of user privacy and integrity of data displayed on other sites.

Affected Systems

Vulnerable versions are those of Mozilla Firefox and Mozilla Thunderbird released before the fixes. The issue was addressed in Firefox 153, and in the ESR branches 115.38 and 140.13 as well as in Thunderbird 153 and its ESR 140.13. Any earlier build is affected.

Risk and Exploitability

The CVSS score of 9.8 signals a very high severity. The EPSS score of less than 1% indicates that active exploitation at present is unlikely, and the vulnerability is not present in CISA’s KEV catalog. The likely attack vector is a malicious web page forcing the browser to use WebRender; an attacker could read or infer content from other sites that share the rendering process.

Generated by OpenCVE AI on August 3, 2026 at 00:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Firefox or Thunderbird 153 or newer (ESR 115.38, ESR 140.13 or later) to receive the fix.
  • If an update cannot be applied immediately, disable the WebRender graphics engine by setting gfx.webrender.enabled to false in about:config, accepting the associated performance impact.
  • Continuously monitor Mozilla security advisories for additional mitigations or updates and apply them promptly.

Generated by OpenCVE AI on August 3, 2026 at 00:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13. Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.
Title Site isolation issue in the Graphics: WebRender component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:42.429Z

Reserved: 2026-07-20T21:56:05.445Z

Link: CVE-2026-16358

cve-icon Vulnrichment

Updated: 2026-07-22T17:09:30.645Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:04.310

Modified: 2026-07-24T15:29:32.250

Link: CVE-2026-16358

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:54Z

Links: CVE-2026-16358 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-346

    Origin Validation Error

  • CWE-368

    Context Switching Race Condition