What is CVE-2026-16349?
CVE-2026-16349 is a same-origin policy bypass vulnerability in the DOM: Navigation component. It affects Firefox and Thunderbird, potentially allowing data leakage. Users must immediately update to Firefox 153, Firefox ESR 115.38/140.13, Thunderbird 153, and Thunderbird 140.13.
Azərbaycanca: CVE-2026-16349, Firefox və Thunderbird-in DOM: Navigation komponentində eyni mənşə (same-origin policy) qorunmasının keçilməsinə imkan verən zəiflikdir. Bu, brauzerlərdə potensial məlumat sızması riski yaradır. İstifadəçilər təcili olaraq Firefox 153, Firefox ESR 115.38/140.13 və Thunderbird 153/140.13 versiyalarına yenilənməlidir.
FAQ2
Which products are affected by CVE-2026-16349?
This vulnerability affects Firefox and Thunderbird.
Which versions should I update to in order to fix CVE-2026-16349?
You must immediately update to Firefox 153, Firefox ESR 115.38/140.13, Thunderbird 153, and Thunderbird 140.13.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.