Mozilla · Firefox · CVE-2026-16353
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 153
Firefox ESR versions prior to 115.38
Firefox ESR versions prior to 140.13
Thunderbird versions prior to 153
Thunderbird version prior to 140.13
**Description**
An invalid pointer exists within the Bindings (WebIDL) component of the DOM. WebIDL (Web Interface Definition Language) is a language used to define the interfaces of web APIs.
**Recommendations**
Update Firefox to version 153 or later.
Update Firefox ESR to version 115.38 or later.
Update Firefox ESR to version 140.13 or later.
Update Thunderbird to version 153 or later.
Update Thunderbird to version 140.13 or later.