Description
Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in a DOM security component that can expose sensitive information to an attacker. It is classified as a CWE‑200 data‑exposure weakness. An attacker may obtain data that should remain private, potentially compromising user confidentiality if the component processes untrusted input.

Affected Systems

Mozilla’s Firefox and Thunderbird applications are affected, specifically all releases prior to version 153. Users on any earlier Firefox or Thunderbird build are vulnerable and require upgrading.

Risk and Exploitability

The CVSS score of 7.5 indicates a medium‑to‑high severity, while the EPSS score of less than 1 % suggests that actual exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through a malicious web page or malicious email that leverages the affected DOM security component. Successful exploitation would allow an attacker to read data that should be protected, but would not provide complete system compromise.

Generated by OpenCVE AI on August 4, 2026 at 05:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Firefox to version 153 or newer.
  • Update Thunderbird to version 153 or newer.
  • Restart the browser applications to ensure the patch takes effect.

Generated by OpenCVE AI on August 4, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153. Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 153.
Title Information disclosure in the DOM: Security component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:05.514Z

Reserved: 2026-07-20T21:57:31.408Z

Link: CVE-2026-16400

cve-icon Vulnrichment

Updated: 2026-07-22T17:23:12.187Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-21T12:38:13Z

Links: CVE-2026-16400 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor