CVE-2026-84641
7.5Mozilla · Thunderbird
A use-after-free and heap-memory disclosure vulnerability in Mozilla Thunderbird allows a malicious IMAP server to leak heap contents into the prefs.js file via a crafted ID response.
Executive summary
A critical vulnerability in Mozilla Thunderbird allows unauthenticated remote attackers to disclose sensitive heap memory, posing a significant risk to user data privacy.
Vulnerability
This vulnerability is a use-after-free and memory disclosure flaw triggered by an unauthenticated attacker operating a malicious IMAP server. By sending a crafted ID response, the attacker can force the application to write heap contents into the configuration file, prefs.js.
Business impact
The ability to disclose heap memory can lead to the exposure of sensitive information, including credentials, tokens, or other private data stored in the application memory. With a CVSS score of 7.5, this high-severity flaw represents a significant risk to organizational data confidentiality, as it can be exploited remotely without user interaction.
Remediation
Immediate Action: Upgrade to Mozilla Thunderbird version 140.15, 153.2, 155, or any later release to incorporate the necessary security patches.
Proactive Monitoring: Review application access logs for connections to untrusted or suspicious mail servers that might attempt to exploit IMAP protocol responses.
Compensating Controls: Ensure that Thunderbird is configured to block remote content and minimize connections to non-essential or untrusted mail servers where possible.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a high risk due to the potential for unauthenticated remote memory disclosure. Security teams should prioritize the deployment of the provided Thunderbird updates across all client workstations immediately to prevent unauthorized access to sensitive memory contents.
More Mozilla CVEs all →
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.5 (3.1)
- Analyst report written
- Published in the daily brief high section, early-warning entry
Sources
Originally found and disclosed by ABDULAZIZ ALASAIQAH, per the CVE Program record.