ZeroHour

CVE-2026-84134

mass

Information disclosure in Mozilla Firefox and Thunderbird Profile Backup

CVSS 3.1
9.8 critical
EPSS
<1%p23
Published
()
Modified
AI analysis

Mozilla fixed an unspecified issue (CVE-2026-84134) in the Profile Backup component shared by its Firefox browser and Thunderbird mail client, classified by Mozilla as an information-exposure flaw (CWE-200) and rated Critical at CVSS 3.1 9.8. The public description is sparse, but the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the issue is reachable over the network without privileges or user interaction. The critical score with high confidentiality, integrity, and availability impact suggests significant potential consequences, though the exact mechanism of the Profile Backup issue has not been publicly detailed. Users running Firefox before 155, Firefox ESR before 153.2, Thunderbird before 155, or Thunderbird before 153.2 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no active exploitation is known.

What to do: Upgrade to Firefox 155, Firefox ESR 153.2, Thunderbird 155, or Thunderbird 153.2 (or later). No workarounds are documented, so patching is the primary mitigation; since no in-the-wild exploitation is known, prioritize within normal patching cycles given the critical severity score.

Affected
mozilla firefoxall versions prior to 155
mozilla firefox-esrall versions prior to 153.2
mozilla thunderbirdall versions prior to 155 and 153.x releases prior to 153.2
Estimated exposure
masshundreds of millions of users (global Firefox/Thunderbird desktop install base; Thunderbird alone has millions of active users) — Firefox maintains a global desktop user base in the hundreds of millions and Thunderbird several million active users, and every release before the fixed versions is affected, though real-world exploitability is limited to the Profile…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.