CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 153 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 153
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-16349
- CVE-2026-16350
- CVE-2026-16362
- CVE-2026-16351
- CVE-2026-16352
- CVE-2026-16363
- CVE-2026-16364
- CVE-2026-16365
- CVE-2026-16366
- CVE-2026-16353
- CVE-2026-16354
- CVE-2026-16367
- CVE-2026-16368
- CVE-2026-16369
- CVE-2026-16355
- CVE-2026-16356
- CVE-2026-16357
- CVE-2026-16370
- CVE-2026-16371
- CVE-2026-16372
- CVE-2026-16373
- CVE-2026-16374
- CVE-2026-16375
- CVE-2026-16376
- CVE-2026-16377
- CVE-2026-16378
- CVE-2026-16379
- CVE-2026-16358
- CVE-2026-16380
- CVE-2026-16381
- CVE-2026-16382
- CVE-2026-16383
- CVE-2026-16384
- CVE-2026-16385
- CVE-2026-16386
- CVE-2026-16387
- CVE-2026-16388
- CVE-2026-16389
- CVE-2026-16390
- CVE-2026-16391
- CVE-2026-16392
- CVE-2026-16393
- CVE-2026-16359
- CVE-2026-16394
- CVE-2026-16395
- CVE-2026-16396
- CVE-2026-16397
- CVE-2026-16398
- CVE-2026-16399
- CVE-2026-16400
- CVE-2026-16401
- CVE-2026-16402
- CVE-2026-16403
- CVE-2026-16404
- CVE-2026-16405
- CVE-2026-16406
- CVE-2026-16407
- CVE-2026-16408
- CVE-2026-16409
- CVE-2026-16410
- CVE-2026-16411
- CVE-2026-16412
- CVE-2026-16360
- CVE-2026-14899
Frequently Asked Questions
What is the severity of CVE-2026-16367?
CVE-2026-16367 has a severity rating of critical, with a CVSS score of 10.
How do I fix CVE-2026-16367?
To address CVE-2026-16367, users should update to Mozilla Firefox version 153 or later.
What impact does CVE-2026-16367 pose?
CVE-2026-16367 could allow an attacker to escape the sandbox, potentially leading to a complete compromise of the system.
Which software is affected by CVE-2026-16367?
CVE-2026-16367 affects Mozilla Firefox and Mozilla Thunderbird.
What type of vulnerability is CVE-2026-16367?
CVE-2026-16367 is categorized as a sandbox escape due to buffer overflow and use after free issues in the Disability Access APIs.