ZeroHour

CVE-2026-84144

mass

Memory corruption bugs in Mozilla Firefox and Thunderbird

CVSS 3.1
7.5 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-84144 describes a set of internally discovered bugs in the shared Gecko codebase, present in Thunderbird 154 and Thunderbird ESR 153.1, showing evidence of memory corruption or another security-relevant defect (CWE-119). The flaws are network-reachable but require user interaction and have high attack complexity, so exploitation is not straightforward; with enough effort, an attacker could potentially achieve high-impact effects on confidentiality, integrity, and availability, likely including code execution. Users running the affected Thunderbird releases, and the corresponding Firefox releases whose code received the same fixes, are exposed until they update. The bugs were fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2. No public proof-of-concept is known, the issue is not in the CISA KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.

What to do: Upgrade to Firefox 155, Firefox ESR 153.2, Thunderbird 155, or Thunderbird 153.2 (ESR 153.2). Use software inventory or endpoint management to confirm no managed systems remain on Thunderbird 154/ESR 153.1 or pre-155 Firefox builds; no workarounds are specified, so updating is the primary mitigation.

Affected
Mozilla Firefoxprior to 155
Mozilla Firefox ESRprior to 153.2
Mozilla Thunderbird154 and all versions prior to 155
Mozilla Thunderbird ESR153.1 and all versions prior to 153.2
Estimated exposure
masstens of millions of users (Mozilla's desktop browser and mail client bases are each in the tens of millions, with the affected versions spanning roughly one… — Firefox has well over 100 million active users and Thunderbird on the order of 20-30 million active installs, so even the fraction running the affected releases at a given time reaches into the millions to tens of millions.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.