What is CVE-2026-16352?
This vulnerability is a sandbox escape caused by a use-after-free in the Disability Access APIs component of Firefox and Thunderbird. It affects earlier versions and is fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13. Users should immediately update to the patched versions.
Azərbaycanca: Bu boşluq Firefox və Thunderbird-də Disability Access API komponentində istifadə-sonrası-sərbəst buraxma (use-after-free) nəticəsində sandbox mühitindən çıxış imkanı yaradır. Bu zəiflik Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153 və Thunderbird 140.13 versiyalarında aradan qaldırılıb. İstifadəçilər dərhal qeyd olunan və ya daha yeni versiyalara yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
Which products are affected by CVE-2026-16352?
This vulnerability affects earlier versions of Firefox and Thunderbird.
What versions should be updated to protect against CVE-2026-16352?
You should update to Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.