CVE-2026-16349

Summary

Same-origin policy bypass in the DOM: Navigation component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, and Firefox ESR 140.13.

Affected Software

VendorProductVersion RangeStatus
MozillaFirefox115.38 <= 115.*unaffected
MozillaFirefox140.13 <= 140.*unaffected
MozillaFirefox153 <= *unaffected

Weaknesses

References