Description
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Firefox and Thunderbird contain a vulnerability that allows attackers to bypass DOM‑based mitigation mechanisms. This weakness, identified as CWE‑693, enables the compromise of the intended security model of the application. Although the detailed exploitation impact is not explicitly described, the bypass could lead to unauthorized actions or data exposure within the affected client. The vulnerability was patched in version 153 of both products.

Affected Systems

All Mozilla Firefox and Thunderbird releases prior to version 153 are affected. The fix was introduced in Firefox 153 and Thunderbird 153, so any higher version is considered safe.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, while the EPSS < 1% shows that exploitation probability is currently low. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through client‑side content such as a malicious web page or email, which can trigger the DOM mitigation bypass. No specific prerequisites are mentioned, so widespread use of older Firefox or Thunderbird versions exposes users to this risk.

Generated by OpenCVE AI on August 3, 2026 at 00:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 153 or newer
  • Upgrade to Mozilla Thunderbird 153 or newer
  • Apply stricter web/email filtering or enable stricter Content Security Policies to reduce exploitation risk until the upgraded versions are deployed.

Generated by OpenCVE AI on August 3, 2026 at 00:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153. Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 153.
Title Mitigation bypass in the DOM: Security component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:18:59.557Z

Reserved: 2026-07-20T21:57:19.701Z

Link: CVE-2026-16394

cve-icon Vulnrichment

Updated: 2026-07-21T19:37:33.249Z

cve-icon NVD

Status : Modified

Published: 2026-07-21T13:17:14.620

Modified: 2026-07-22T20:16:57.700

Link: CVE-2026-16394

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:08Z

Links: CVE-2026-16394 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:00:04Z

Weaknesses
  • CWE-358

    Improperly Implemented Security Check for Standard

  • CWE-693

    Protection Mechanism Failure