Use-After-Free Vulnerability in Thunderbird by Mozilla
CVE-2026-84641

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
1 September 2026

What is CVE-2026-84641?

A vulnerability exists in Mozilla's Thunderbird email client, where a malicious IMAP server can exploit a crafted ID response to trigger a use-after-free condition. This may lead to heap memory disclosure, allowing sensitive information to be leaked and persisted in the prefs.js file, potentially compromising user privacy and data security.

Affected Version(s)

Thunderbird 140.15

Thunderbird 153.2

Thunderbird 155

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ABDULAZIZ ALASAIQAH
.