Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16388: Firefox Networking Component Sandbox Escape

CVE-2026-16388 CVE-2026-16388
Summary

A bug in Firefox's networking component allows an attacker to break out of the secure sandbox, potentially allowing malicious code to access sensitive information. This issue was fixed in Firefox version 153, so updating to this version or later is recommended to prevent exploitation.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
mozilla firefox All versions
Original title
Sandbox escape in the DOM: Networking component
Original description
Sandbox escape in the DOM: Networking component. This vulnerability was fixed in Firefox 153.
Vulnerability type
CWE-693 Protection Mechanism Failure
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026