What is CVE-2026-16374?
CVE-2026-16374 is an information disclosure vulnerability within the Framework component of DevTools in Firefox and Thunderbird products. This flaw could allow unauthorized access to information, and it has been fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.
Azərbaycanca: CVE-2026-16374 Firefox, Firefox ESR və Thunderbird-in DevTools-da Framework komponentində məlumat sızması zəifliyidir. Bu boşluq vasitəsilə məxfi məlumat əldə oluna bilər, təsirlənən proqramları qeyd olunan son versiyalara yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which products are affected by CVE-2026-16374?
CVE-2026-16374 affects Firefox, Firefox ESR, and Thunderbird products within their DevTools Framework component.
How can CVE-2026-16374 be mitigated?
This information disclosure flaw is fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13, so updating to these or later versions mitigates it.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.