VYPR
Critical severity9.8NVD Advisory· Published Jul 21, 2026· Updated Jul 24, 2026

CVE-2026-16356

CVE-2026-16356

Description

Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.

Affected products

21

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.