Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16396: Firefox Privilege Escalation in WebExtensions

CVE-2026-16396 CVE-2026-16396
Summary

A security issue in Firefox's WebExtensions allowed malicious add-ons to gain elevated permissions. This has been fixed in Firefox 153 and Firefox ESR 140.13, so you should update to these versions if you're running an affected version of the browser.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
mozilla firefox All versions
Original title
Privilege escalation in WebExtensions
Original description
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Vulnerability type
CWE-269 Improper Privilege Management
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026