Description
Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information‑disclosure flaw in the Framework component of DevTools, which can expose sensitive data to an attacker. The flaw is classified as CWE‑200 and allows an attacker to read data that should be protected, such as files, environment variables, or network traffic captured by DevTools. The potential consequences are loss of confidentiality for the user or compromised application data. Based on the description, the vulnerability is likely exploitable by an attacker who can access the DevTools environment, for example a local user who has control over the browser process or who can initiate a remote debugging session.

Affected Systems

Mozilla Firefox and Mozilla Thunderbird are affected, including both the standard releases and the ESR channel. The fix is implemented in Firefox 153, Firefox ESR 140.13, Thunderbird 153 and Thunderbird ESR 140.13. All earlier releases remain vulnerable.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact that does not meet the highest severity but still requires attention. The EPSS score of less than 1% shows that real‑world exploitation is expected to be rare, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is local or via a compromised remote debugging session; additional conditions such as the attacker having access to the DevTools interface are required. The combination of a moderate exploitation probability and high confidentiality impact suggests a prudent approach to mitigation.

Generated by OpenCVE AI on August 3, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Firefox 153 or newer, or Firefox ESR 140.13 or newer; upgrade Thunderbird to 153 or newer, or Thunderbird ESR 140.13 or newer.
  • Disable the DevTools remote debugging interface by setting the preference `devtools.remote.enabled` to `false`, or by preventing remote debugging port exposure.
  • Restrict local access to the DevTools by setting the preference `devtools.enabled` to `false`, or by configuring group policy or local policy settings to block developer tools.

Generated by OpenCVE AI on August 3, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4695-1 firefox-esr security update
Debian DLA Debian DLA DLA-4727-1 thunderbird security update
Debian DSA Debian DSA DSA-6394-1 firefox-esr security update
Debian DSA Debian DSA DSA-6418-1 thunderbird security update
History

Fri, 24 Jul 2026 00:30:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
References

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the Framework component in DevTools. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Title Information disclosure in the Framework component in DevTools
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:35.967Z

Reserved: 2026-07-20T21:56:36.642Z

Link: CVE-2026-16374

cve-icon Vulnrichment

Updated: 2026-07-22T15:42:29.005Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T13:17:12.573

Modified: 2026-07-24T15:19:25.657

Link: CVE-2026-16374

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:37:49Z

Links: CVE-2026-16374 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-215

    Insertion of Sensitive Information Into Debugging Code