What is CVE-2026-16367?
CVE-2026-16367 is a sandbox escape vulnerability caused by an invalid pointer in the Disability Access APIs component of Firefox and Thunderbird. This issue was fixed in version 153 of both products, so users should update immediately to mitigate the risk.
Azərbaycanca: CVE-2026-16367, Firefox və Thunderbird proqramlarının "Disability Access APIs" komponentindəki etibarsız göstərici (invalid pointer) səbəbindən sandbox mühitindən qaçmağa imkan verən boşluqdur. Bu zəiflik Firefox 153 və Thunderbird 153 versiyalarında aradan qaldırılıb, ona görə də istifadəçilərə dərhal bu versiyalara yeniləmə tövsiyə olunur.
FAQ2
Which products are affected by CVE-2026-16367?
This vulnerability was discovered in the "Disability Access APIs" component of Firefox and Thunderbird.
To which versions should users update to mitigate CVE-2026-16367?
This issue was fixed in Firefox 153 and Thunderbird 153.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.