Description
Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Mozilla’s Firefox and Thunderbird? DOM navigation component improperly enforces site isolation, allowing maliciously crafted content to break isolation boundaries between distinct browsing contexts. This weakness, classified as CWE‑346 Authentication Bypass, can enable an attacker to read data that should remain confined to another site or application, potentially leading to disclosure of sensitive information.

Affected Systems

Mozilla’s Firefox and Thunderbird products are vulnerable in any release older than version 153; users who have not updated to Firefox 153 or Thunderbird 153 remain exposed to the site isolation flaw.

Risk and Exploitability

The flaw carries a CVSS score of 7.5, indicating high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The likely attack vector is remote, via crafted web content or a compromised site, although the description does not detail an explicit exploitation path.

Generated by OpenCVE AI on August 4, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Firefox to version 153 or newer to receive the fix for the site isolation issue.
  • Upgrade Thunderbird to version 153 or newer to eliminate the vulnerability.
  • Regularly monitor Mozilla security advisories for additional patches or guidance on related vulnerabilities.

Generated by OpenCVE AI on August 4, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Thu, 23 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla thunderbird
Vendors & Products Mozilla
Mozilla firefox
Mozilla thunderbird

Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153. Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-346
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 153.
Title Site isolation issue in the DOM: Navigation component
References

Subscriptions

Mozilla Firefox Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:04.320Z

Reserved: 2026-07-20T21:57:29.336Z

Link: CVE-2026-16399

cve-icon Vulnrichment

Updated: 2026-07-22T17:22:14.171Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:12Z

Links: CVE-2026-16399 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:00:14Z

Weaknesses