Executive brief
Thunderbird, a widely-used email and messaging client, contains multiple internally discovered security bugs related to memory corruption. These defects could potentially allow attackers to crash the application or execute arbitrary code if successfully exploited, compromising user privacy and system security.
Technical details
Multiple internally discovered bugs involving memory corruption and other security-relevant defects were found in Thunderbird's rendering and browser engine components. The exact attack vector depends on the specific bug, but these are presumed exploitable given sufficient effort. These vulnerabilities affect Thunderbird versions 154 and ESR 153.1. Patches are available in Thunderbird 155 and Thunderbird ESR 153.2.
Affected products
- Mozilla Thunderbird 154
- Mozilla Thunderbird ESR 153.1
Timeline
- 2026-09-01: disclosed: CVE-2026-84144 published
- 2026-09-01: patched: Fixed in Thunderbird 155 and Thunderbird ESR 153.2
References
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054619%2C2054620%2C2054624%2C2054702%2C2054726%2C2054775%2C2055703%2C2058006%2C2058013%2C2058098%2C2058627%2C2058661%2C2059127%2C2059128%2C2059180%2C2059199%2C2059205%2C2061320%2C2061430%2C2061495%2C2061505%2C2061532%2C2061799
- https://bugzilla.mozilla.org/buglist.cgi?bug_id=2054625%2C2059002%2C2061775