CVE-2026-84134
massInformation disclosure in Mozilla Firefox and Thunderbird Profile Backup
Mozilla fixed an unspecified issue (CVE-2026-84134) in the Profile Backup component shared by its Firefox browser and Thunderbird mail client, classified by Mozilla as an information-exposure flaw (CWE-200) and rated Critical at CVSS 3.1 9.8. The public description is sparse, but the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates the issue is reachable over the network without privileges or user interaction. The critical score with high confidentiality, integrity, and availability impact suggests significant potential consequences, though the exact mechanism of the Profile Backup issue has not been publicly detailed. Users running Firefox before 155, Firefox ESR before 153.2, Thunderbird before 155, or Thunderbird before 153.2 are affected. There is currently no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no active exploitation is known.
What to do: Upgrade to Firefox 155, Firefox ESR 153.2, Thunderbird 155, or Thunderbird 153.2 (or later). No workarounds are documented, so patching is the primary mitigation; since no in-the-wild exploitation is known, prioritize within normal patching cycles given the critical severity score.
| mozilla firefox | all versions prior to 155 |
| mozilla firefox-esr | all versions prior to 153.2 |
| mozilla thunderbird | all versions prior to 155 and 153.x releases prior to 153.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.