Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-16396: Firefox Privilege Escalation in WebExtensions
CVE-2026-16396
CVE-2026-16396
Summary
A security issue in Firefox's WebExtensions allowed malicious add-ons to gain elevated permissions. This has been fixed in Firefox 153 and Firefox ESR 140.13, so you should update to these versions if you're running an affected version of the browser.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mozilla | firefox | All versions |
Original title
Privilege escalation in WebExtensions
Original description
Privilege escalation in WebExtensions. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
Vulnerability type
CWE-269
Improper Privilege Management
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 21 Jul 2026