Executive brief
Thunderbird, a widely-used email and calendar client, contains multiple internally discovered bugs that can cause memory corruption or other security vulnerabilities. An attacker with sufficient effort could potentially exploit these flaws to crash the application, execute arbitrary code, or compromise user data and email communications. Mozilla has released patches to address these issues across multiple Thunderbird versions.
Technical details
This vulnerability encompasses multiple memory corruption and security-related defects discovered by Mozilla's internal security team in the Thunderbird email client. The bugs involve memory safety issues across multiple components in affected versions. The vulnerabilities require no user interaction beyond normal email client usage, as they can be triggered through malicious content or network interactions. An attacker can achieve code execution, denial of service, or information disclosure depending on the specific underlying defect. Patches are available in Thunderbird 155, 140.15, and 153.2.
Affected products
- Mozilla Thunderbird 154
- Mozilla Thunderbird ESR 153.1, 140.14
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Fixed in Thunderbird 155, 140.15, and 153.2