CVE-2026-84641
massUse-after-free and heap-memory disclosure in Thunderbird IMAP ID handling
Thunderbird contains a use-after-free (CWE-416) in its handling of the IMAP ID extension: a malicious or compromised IMAP server can send a specially crafted ID response that triggers the flaw and causes heap memory to be disclosed. An attacker gains read access to process heap contents, which can ultimately be persisted into the user's prefs.js file, exposing potentially sensitive data; the vulnerability has no integrity or availability impact. Users are affected when they connect to an IMAP server that is attacker-controlled, compromised, or spoofed, making mail users with IMAP accounts the primary exposure population. As of now there is no known public proof-of-concept, the CISA KEV catalog does not list it, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days, so no active exploitation is known.
What to do: Upgrade Thunderbird to 155, 140.15, or 153.2 depending on your release branch. As an interim mitigation, avoid connecting to untrusted or unencrypted IMAP servers, and inspect prefs.js (and leaked heap data) on systems that connected to potentially hostile servers to check for unexpectedly persisted sensitive strings.
| mozilla thunderbird | All versions prior to 155, including releases on the ESR branch prior to 140.15 and on the prior stable branch prior to 153.2 (fixed in Thunderbird 155, 140.15, |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.
- Vendors
- mozilla
- Products
- thunderbird
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.