Description
Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A mitigation bypass vulnerability was identified in the Service Workers component of Mozilla's DOM handling. The description states that the browser’s built‑in security checks can be overridden, allowing an attacker to bypass intended authorization controls. This flaw involves improper authorization (CWE‑284), insecure persistence mechanisms (CWE‑693), and potential data leakage (CWE‑807).

Affected Systems

The flaw impacts Mozilla Firefox and Mozilla Thunderbird. Versions prior to 153 are affected; upgrading to Firefox 153 or later, or Thunderbird 153 or later, eliminates the issue.

Risk and Exploitability

The CVSS score of 9.8 classifies the bug as critical, while the EPSS score of <1% indicates a low likelihood of exploitation at the time of assessment. The vulnerability is not listed in CISA KEV. Based on the description of a mitigation bypass, it is inferred that a malicious website could register a compromised Service Worker in a user’s browser, leading the worker to override security checks. No definitive attack steps are provided in the CVE text, so the exact exploitation path remains speculative.

Generated by OpenCVE AI on August 3, 2026 at 00:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Mozilla Firefox 153 or later, or Mozilla Thunderbird 153 or later, which contain the fix for this issue.
  • If an upgrade cannot be performed immediately, disable Service Workers by setting security.service_worker.enabled to false in about:config to block the vulnerable feature.
  • Monitor for anomalous network activity or redirected requests originating from Service Workers, which may indicate exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 00:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 00:15:00 +0000


Wed, 22 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153. Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
References

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-693
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Vendors & Products Mozilla
Mozilla firefox

Tue, 21 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Description Mitigation bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 153.
Title Mitigation bypass in the DOM: Service Workers component
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-07-22T19:19:13.083Z

Reserved: 2026-07-20T21:57:45.957Z

Link: CVE-2026-16407

cve-icon Vulnrichment

Updated: 2026-07-22T18:02:00.953Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-21T12:38:19Z

Links: CVE-2026-16407 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:45:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-693

    Protection Mechanism Failure

  • CWE-807

    Reliance on Untrusted Inputs in a Security Decision