CVE-2019-9816: Mozilla Firefox

Medium severity, CVSS 5.9. EPSS: 6.2% chance of exploitation in the next 30 days.

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

Affected products

  • Mozilla Firefox: before 67.0 (fixed in 67.0)
  • Mozilla Firefox ESR: before 60.7 (fixed in 60.7)
  • Mozilla Thunderbird: before 60.7 (fixed in 60.7)

Published 2019-07-23. Last modified 2026-06-17.