Executive brief
Thunderbird is a widely-used open-source email and messaging client. Mozilla discovered multiple internal security flaws involving memory corruption and other defects that could potentially be exploited by attackers to crash the application, corrupt data, or execute arbitrary code. Updates are available to address these issues.
Technical details
This vulnerability encompasses multiple internally discovered bugs in Thunderbird and Firefox with evidence of memory corruption and security-relevant defects. The vulnerable components span various subsystems within the Thunderbird email client and Firefox browser engine. These bugs are exploitable remotely without authentication or user interaction under certain conditions. An attacker could leverage these vulnerabilities to achieve arbitrary code execution, memory disclosure, or denial of service. Patches are available in Thunderbird 154, Thunderbird 153.1, Thunderbird ESR 140.14, and corresponding Firefox releases.
Affected products
- Mozilla Thunderbird ESR 140.13, ESR 153.0, 153
- Mozilla Firefox ESR 115.x (before 115.39), ESR 140.13, ESR 153.0
Timeline
- 2026-08-18: disclosed: Vulnerability disclosed via NVD
- 2026-08-18: patched: Fixes available in Thunderbird 154, 153.1, ESR 140.14; Firefox 154, ESR 115.39, ESR 140.14, ESR 153.1
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045762%2C2052401%2C2058208
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2045774%2C2048490%2C2050864%2C2053159%2C2053260%2C2053261%2C2053582%2C2053599%2C2053607%2C2053608%2C2053853%2C2054626%2C2054627%2C2054635%2C2054677%2C2054740%2C2054832%2C2056792%2C2057098%2C2057100%2C2057101%2C2057103%2C2057117%2C2057118%2C2058048%2C2058049%2C2058622%2C2058623%2C2058665%2C2058666%2C2059121%2C2059164%2C2059188