CVE-2026-84141
massInteger overflow in Mozilla Firefox and Thunderbird image decoding (ImageLib)
CVE-2026-84141 is an integer overflow (CWE-190) in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, which is responsible for decoding image content. The flaw is triggered when a vulnerable client processes specially crafted image data, such as an image embedded in a web page or an email, and the numeric overflow can lead to memory corruption during decoding. An attacker who induces a user's browser or mail client to decode the malicious image may gain high-impact consequences consistent with the CVSS 9.8 rating, potentially including arbitrary code execution or a crash (denial of service). All Firefox and Thunderbird users running releases prior to the fixed versions are affected, including both the rapid-release and ESR branches. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in the CISA KEV catalog, with EPSS estimating only about a 0.3% chance of exploitation within 30 days.
What to do: Update Firefox to 155 or later and Firefox ESR to 153.2 or later; update Thunderbird to 155 or later and Thunderbird ESR to 153.2 or later. Because most users receive browser and mail-client updates automatically, verify the installed version rather than assuming patching has occurred, and prioritize systems that regularly render untrusted web or email content.
| mozilla firefox | versions before 155 (fixed in Firefox 155) |
| mozilla firefox-esr | versions before 153.2 (fixed in Firefox ESR 153.2) |
| mozilla thunderbird | versions before 155 (fixed in Thunderbird 155) |
| mozilla thunderbird-esr | versions before 153.2 (fixed in Thunderbird 153.2) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- firefox, thunderbird
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.