ZeroHour

CVE-2026-84141

mass

Integer overflow in Mozilla Firefox and Thunderbird image decoding (ImageLib)

CVSS 3.1
9.8 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

CVE-2026-84141 is an integer overflow (CWE-190) in the Graphics: ImageLib component of Mozilla Firefox and Thunderbird, which is responsible for decoding image content. The flaw is triggered when a vulnerable client processes specially crafted image data, such as an image embedded in a web page or an email, and the numeric overflow can lead to memory corruption during decoding. An attacker who induces a user's browser or mail client to decode the malicious image may gain high-impact consequences consistent with the CVSS 9.8 rating, potentially including arbitrary code execution or a crash (denial of service). All Firefox and Thunderbird users running releases prior to the fixed versions are affected, including both the rapid-release and ESR branches. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in the CISA KEV catalog, with EPSS estimating only about a 0.3% chance of exploitation within 30 days.

What to do: Update Firefox to 155 or later and Firefox ESR to 153.2 or later; update Thunderbird to 155 or later and Thunderbird ESR to 153.2 or later. Because most users receive browser and mail-client updates automatically, verify the installed version rather than assuming patching has occurred, and prioritize systems that regularly render untrusted web or email content.

Affected
mozilla firefoxversions before 155 (fixed in Firefox 155)
mozilla firefox-esrversions before 153.2 (fixed in Firefox ESR 153.2)
mozilla thunderbirdversions before 155 (fixed in Thunderbird 155)
mozilla thunderbird-esrversions before 153.2 (fixed in Thunderbird 153.2)
Estimated exposure
masson the order of hundreds of millions of users (Firefox alone has roughly 200-300 million monthly active users, plus tens of millions of Thunderbird installs) — Mozilla's publicly reported Firefox monthly active-user counts are in the hundreds of millions and Thunderbird has tens of millions of users, so any pre-fix installations of these mainstream desktop clients represent a mass-scale affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.