Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-106016: Firefox file handling can skip security checks

CVE-2026-106016 · published 4 days ago
Summary

A mistake in Firefox’s file handling code could let malicious files avoid security protections. The issue also affects several Mozilla JavaScript engine versions packaged by Canonical. Updating Firefox to version 157.0.1 or later (and applying updates to the related mozjs packages) resolves the problem.

What to do
  • Update mozilla firefox to version 157.0.1 or later.
Affected software
Ecosystem VendorProductAffected versions
– mozilla firefox < 157.0.1
Ubuntu:18.04:LTS canonical mozjs52 All versions
Ubuntu:18.04:LTS canonical mozjs38 All versions
Ubuntu:20.04:LTS canonical mozjs68 All versions
Ubuntu:22.04:LTS canonical mozjs102 All versions
Ubuntu:22.04:LTS canonical mozjs78 All versions
Ubuntu:22.04:LTS canonical mozjs91 All versions
Ubuntu:22.04:LTS canonical thunderbird All versions
Ubuntu:24.04:LTS canonical mozjs115 All versions
Original advisory text
Mitigation bypass in the File Handling component
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 157.0.1.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-693Protection Mechanism Failure
Timeline
Published6 Oct 2026
Updated10 Oct 2026
First seen6 Oct 2026
Sources
CVE-2026-106016 · MITRE
Track software like this
Free during beta