ZeroHour

CVE-2026-84142

mass

Memory corruption bugs in Mozilla Firefox and Thunderbird (fixed in 155)

CVSS 3.1
9.8 critical
EPSS
<1%p23
Published
()
Modified
AI analysis

CVE-2026-84142 is a Mozilla advisory covering multiple internally discovered bugs in Thunderbird 154, some showing evidence of memory corruption (CWE-119) or other security-relevant defects, with possible information exposure (CWE-200). The flaws are network-reachable with no privileges or user interaction required per the CVSS vector, meaning an attacker could potentially trigger them through content processed by the browser or mail client, and with sufficient effort could have gained code execution or access to sensitive information. Users running Firefox or Thunderbird versions prior to 155 are affected. The issues were fixed in Firefox 155 and Thunderbird 155. There is no known public proof-of-concept, no CISA KEV listing, and only a low estimated exploitation probability (EPSS 0.3%), so no in-the-wild exploitation is currently known.

What to do: Upgrade Firefox to 155 and Thunderbird to 155, which are the fixed releases; verify installed versions rather than assuming auto-update has completed. No workarounds are described, but until patching, avoid opening untrusted web content or email attachments in affected builds. No in-the-wild exploitation is known, so this can be patched in normal cycles, though the critical CVSS score justifies prompt updates on endpoints handling untrusted content.

Affected
mozilla firefoxversions prior to 155
mozilla thunderbirdversions prior to 155 (bugs described in Thunderbird 154)
Estimated exposure
masshundreds of millions of users (Firefox's global active user base is on the order of 200M+, with Thunderbird adding millions of desktop installs) — Mozilla's publicly reported usage statistics put Firefox's active installations in the hundreds of millions worldwide, and Thunderbird is a widely deployed desktop mail client, so the installed base dwarfs any per-flaw segmentation.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-119, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.