# Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405)

> CVE-2026-16405 is a high-severity (CVSS 7.5) information disclosure vulnerability in Mozilla Firefox's and Thunderbird's Networking: WebSockets component. A remote, unauthenticated attacker can leak sensitive data without user interaction by exploiting incorrect handling in the WebSocket protocol stack. The vulnerability is automatable per CISA SSVC assessment, though no exploitation in the wild has been reported as of publication. Fixed in Firefox 153, Firefox ESR 140.13, Thunderbird 153, and Thunderbird ESR 140.13, all released July 21, 2026.

- **Published:** 2026-08-04T00:00:00Z
- **Last reviewed:** 2026-08-04T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1878
- **ID:** TL-2026-1878
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-16405

## Description

CVE-2026-16405 is an information disclosure vulnerability (CWE-200) residing in Mozilla Firefox's Networking: WebSockets component — the implementation of the ws:// and wss:// protocol stacks layered over the HTTP upgrade mechanism. Discovered and reported by security researcher Yaqoub Aldurayhim, the flaw was addressed in the July 21, 2026 release of Firefox 153 (MFSA2026-68) and subsequently expanded to cover Thunderbird (MFSA2026-71, MFSA2026-72) and Firefox ESR (MFSA2026-70).

The vulnerability arises from a defect in the WebSocket networking path's framing, buffer management, or state handling. Unlike standard HTTP requests (which are subject to Same-Origin Policy read restrictions enforced by the browser), WebSockets are designed to provide full-duplex communication channels that cross origins by design — the browser automatically attaches cookies and credentials to the WebSocket handshake. A flaw in how Firefox processes these connections at the networking layer can cause it to leak sensitive information from the browser's process memory, cross-origin response data, or connection state that should remain isolated. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N confirms the vulnerability is network-exploitable, requires no privileges or user interaction (beyond the victim visiting a page), and carries a high confidentiality impact.

CISA's ADP enrichment assigned a CVSS v3.1 base score of 7.5 (High) along with CWE-200 classification, and performed an SSVC assessment rating Exploitation as 'none', Automatable as 'yes', and Technical Impact as 'partial'. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog as of August 4, 2026, and carries a low EPSS score of 0.256% (17th percentile), indicating a low near-term exploitation probability. However, the automatable rating means that once a working exploit is developed, it could be deployed at scale without manual per-target intervention.

The fix was shipped as part of a significant security release: Firefox 153 also enabled Local Network Access restrictions by default and introduced new extension permission controls for local file access. The underlying Bugzilla report (Bug 2036591) remains restricted from public access, limiting external technical analysis. Mozilla's own advisory rates this vulnerability as 'Low' in their internal severity scale, though the CVSS score from CISA ADP is 7.5 (High). The scope of affected products was expanded within 24 hours of original publication to include Thunderbird across both release and ESR channels.

Organizations running Firefox, Firefox ESR, Thunderbird, or Thunderbird ESR should prioritize upgrading to the fixed versions (153 or 140.13+ respectively) as the primary remediation. As a compensating control, network administrators can restrict outbound WebSocket connections (ws://, wss://) to untrusted destinations at the proxy or firewall level, though this may disrupt legitimate real-time web applications.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1566 Phishing
- T1059 Command and Scripting Interpreter
- T1539 Steal Web Session Cookie
- T1528 Steal Application Access Token
- T1005 Data from Local System
- T1119 Automated Collection
- T1071 Application Layer Protocol

## Sources

- [Mozilla Foundation Security Advisory 2026-68 (Firefox 153)](https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/)
- [Mozilla Foundation Security Advisory 2026-70 (Firefox ESR 140.13)](https://www.mozilla.org/security/advisories/mfsa2026-70/)
- [Mozilla Foundation Security Advisory 2026-71 (Thunderbird 153)](https://www.mozilla.org/security/advisories/mfsa2026-71/)
- [Mozilla Foundation Security Advisory 2026-72 (Thunderbird ESR 140.13)](https://www.mozilla.org/security/advisories/mfsa2026-72/)
- [NVD — CVE-2026-16405](https://nvd.nist.gov/vuln/detail/CVE-2026-16405)
- [Bugzilla Bug 2036591](https://bugzilla.mozilla.org/show_bug.cgi?id=2036591)
- [GitHub Advisory GHSA-cjjv-h8qx-pq7p](https://github.com/advisories/GHSA-cjjv-h8qx-pq7p)
- [Firefox 153 Release Notes](https://www.mozilla.org/en-US/firefox/153.0/releasenotes/)
- [Firefox 153 Developer Release Notes (MDN)](https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Releases/153)
- [HKCERT Security Bulletin — Mozilla Firefox Information Disclosure Vulnerability](https://www.hkcert.org/security-bulletin/mozilla-firefox-information-disclosure-vulnerability_20260805)
- [CISA Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1878
