Executive brief
Thunderbird, a popular open-source email and calendar client used by millions worldwide, contained multiple internally-discovered security bugs that could lead to memory corruption. An attacker exploiting these flaws could potentially execute arbitrary code or crash the application, compromising user email data and system integrity. Mozilla fixed these issues in Thunderbird 154 and Thunderbird 153.1.
Technical details
Multiple memory corruption and security-relevant defects were discovered through internal testing in Thunderbird ESR 153.0 and Thunderbird 153, affecting the core email and calendar client engine. The vulnerabilities stem from unspecified memory safety issues within the product, allowing potential code execution or denial of service depending on the specific flaw. No network access or user interaction is required if the attacker can reach the affected code paths. The vulnerabilities were patched in Thunderbird 154 and Thunderbird 153.1; users should upgrade immediately. There is no evidence of active exploitation in the wild at the time of disclosure.
Affected products
- Mozilla Thunderbird 153.0
- Mozilla Thunderbird ESR 153.0
Timeline
- 2026-08-18: disclosed: Publicly disclosed via NVD
- 2026-08-18: patched: Fixed in Thunderbird 154 and Thunderbird 153.1
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2018164%2C2045404%2C2045507%2C2045711%2C2052403%2C2053174%2C2054643%2C2054667%2C2054671%2C2054674%2C2054687%2C2054717%2C2054761%2C2054787%2C2055676%2C2056779%2C2056781%2C2058629%2C2059019%2C2059138
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045796%2C2046734%2C2051424%2C2054721%2C2057994%2C2058094%2C2058611%2C2058615%2C2058616%2C2061315