ZeroHour

CVE-2026-84145

mass

Memory corruption bugs in Mozilla Thunderbird and Firefox fixed in 155/153.2/140.15

CVSS 3.1
7.5 high
EPSS
<1%p30
Published
()
Modified
AI analysis

Mozilla fixed a set of internally discovered bugs in Thunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14, several of which showed evidence of memory corruption (CWE-119) that Mozilla presumes could be exploited with sufficient attacker effort. Because Thunderbird and Firefox share the affected code, fixes were shipped for both products; the bugs would be triggered by untrusted content such as a malicious web page, email message, or attachment opened in the application, with user interaction required. Successful exploitation could yield a high-impact compromise of confidentiality, integrity, and availability (CVSS 3.1: 7.5 high, with network vector, high attack complexity, and no privileges required). Anyone running the affected builds — Thunderbird 154, ESR 153.1, or ESR 140.14, and Firefox releases preceding the fixed builds 155 and ESR 115.40/140.15/153.2 — is affected. There is no evidence of exploitation in the wild and no public proof-of-concept; EPSS estimates roughly a 0.4% chance of exploitation within 30 days.

What to do: Upgrade Firefox to 155, or on the ESR branches to 115.40, 140.15, or 153.2, and upgrade Thunderbird to 155, 153.2, or 140.15 as applicable to your branch. Inventory managed endpoints for Thunderbird 154/ESR 153.1/ESR 140.14 and the corresponding Firefox builds, prioritizing mail clients since email-borne content is a likely trigger. No public exploits or workarounds are known, so prompt patching before users open untrusted content is the primary mitigation.

Affected
mozilla thunderbirdThunderbird 154, Thunderbird ESR 153.1, and Thunderbird ESR 140.14; fixed in Thunderbird 155, Thunderbird 153.2, and Thunderbird 140.15
mozilla firefoxBuilds predating the fixed releases: Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2 (the advisory enumerates the fixed versions; ind
Estimated exposure
masslikely millions to tens of millions of users on the affected builds (estimate, not a measured count) — Firefox and Thunderbird each have very large installed bases (Firefox on the order of hundreds of millions of users and Thunderbird in the tens of millions), and fixes span three ESR branches plus the current rapid-release channel, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

Vendors
mozilla
Products
firefox, thunderbird
Weakness
CWE-119
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.