Use-After-Free Vulnerability in Thunderbird by Mozilla
CVE-2026-84641
Currently unrated
What is CVE-2026-84641?
A vulnerability exists in Mozilla's Thunderbird email client, where a malicious IMAP server can exploit a crafted ID response to trigger a use-after-free condition. This may lead to heap memory disclosure, allowing sensitive information to be leaked and persisted in the prefs.js file, potentially compromising user privacy and data security.
Affected Version(s)
Thunderbird 140.15
Thunderbird 153.2
Thunderbird 155