Skip to content

CVE-2026-16356: Mozilla Firefox Use-After-Free in Accessibility APIs

HERMES

HERMES THREAT SCORE & ACCESSIBILITY SUBSYSTEM UAF

Target: Mozilla Firefox Accessibility Subsystem (AccessibleHandler / IA2)
Confidence: 98%
91 / 100
CRITICAL

Measures real-world operational relevance, exploit weaponization, and active threat posture.

Dimension Breakdown
Exploitability 19 / 20
Threat Activity 17 / 20
Weaponization 19 / 20
Exposure 18 / 20
Prevalence 20 / 20
Impact 19 / 20
Exploit Maturity 18 / 20
Attack Chain Potential 19 / 20
βš–οΈ Divergence & Operational Rationale

Hermes rates CVE-2026-16356 at Critical severity (HTS 91). Accessibility subsystems cross process sandboxing boundaries because screen readers and assistive tech require elevated IPC access, making Use-After-Free flaws prime candidates for browser sandbox escapes.

πŸ•ΈοΈ Connected Knowledge Graph & Provenance

CVE-2026-16356: Mozilla Firefox Use-After-Free in Accessibility APIsVULNERABILITY

Connected Nodes: 1
Active Relationships (Outgoing)
→ affectsPRODUCTMicrosoft Windows & Windows Server
98% VERY_HIGH

Software platform affected by security vulnerabilities and agentic attack patterns.

πŸ” Why is this related? (Evidence & Provenance)

“Confirmed security vulnerability in Microsoft Windows & Windows Server documented in Hermes dossier.”

Supporting Verified Evidence:

MetricTechnical SpecificationOperational Impact
CVE IdentifierCVE-2026-16356Standardized vulnerability identifier
Affected SubsystemDisability Access APIsAssistive technology interface
Fixed ReleasesFirefox 153, Firefox ESR 140.13, ESR 115.38Vendor security release
Associated CWECWE-416: Use After FreeHeap memory corruption
  1. Apply Browser Upgrade: Upgrade to Firefox 153 or Firefox ESR 140.13.
  2. Review Assistive Tools: Audit third-party software leveraging Windows IAccessible2 or Linux AT-SPI.