Mozilla Foundation Security Advisory 2026-78
Security Vulnerabilities fixed in Thunderbird 154
- Announced
- August 18, 2026
- Impact
- high
- Products
- Thunderbird
- Fixed in
-
- Thunderbird 154
In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
#CVE-2026-75874: Sandbox escape in the Remote Settings Client component
- Reporter
- crixer
- Impact
- high
References
#CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component
- Reporter
- satyamasd
- Impact
- high
References
#CVE-2026-74935: Privilege escalation in the DOM: Networking component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74937: Use-after-free in the JavaScript: GC component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74938: Mitigation bypass in the JavaScript: GC component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74939: Privilege escalation in the DOM: Navigation component
- Reporter
- choeseyeong
- Impact
- high
References
#CVE-2026-74940: Use-after-free in the Graphics: Text component
- Reporter
- kiyong
- Impact
- high
References
#CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component
- Reporter
- Jacolon Walker
- Impact
- high
References
#CVE-2026-74942: Privilege escalation in the Remote Settings Client component
- Reporter
- Gal Ankonina
- Impact
- high
References
#CVE-2026-74943: Use-after-free in the Graphics: ImageLib component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- high
References
#CVE-2026-74944: Use-after-free in the DOM: Core & HTML component
- Reporter
- Amy Burnett of OpenAI
- Impact
- high
References
#CVE-2026-74945: Information disclosure in the Graphics: Text component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- high
References
#CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component
- Reporter
- locust1b
- Impact
- high
References
#CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component
- Reporter
- navapon
- Impact
- high
References
#CVE-2026-74948: Information disclosure in the Graphics component
- Reporter
- Yaqoub Aldurayhim
- Impact
- high
References
#CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component
- Reporter
- r00tdaddy
- Impact
- high
References
#CVE-2026-74950: Privilege escalation in the Downloads API component
- Reporter
- Frederik Braun
- Impact
- moderate
References
#CVE-2026-74952: Privilege escalation in the Application Update component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74953: Privilege escalation in the Networking: Cookies component
- Reporter
- Satoki Tsuji
- Impact
- moderate
References
#CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74955: Privilege escalation in the Request Handling component
- Reporter
- jmwebdevelopement
- Impact
- moderate
References
#CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component
- Reporter
- pakhunov.anton.n
- Impact
- moderate
References
#CVE-2026-74957: Mitigation bypass in the Safe Browsing component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74958: Information disclosure in the WebRTC component
- Reporter
- Tomoya Nakanishi
- Impact
- moderate
References
#CVE-2026-74959: Mitigation bypass in the Storage: Cache API component
- Reporter
- David Bors at Snyk Security Labs
- Impact
- moderate
References
#CVE-2026-74960: Site isolation issue in the WebExtensions component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-74961: Side-channel in the Web Audio component
- Reporter
- Rintaro Kawasugi
- Impact
- moderate
References
#CVE-2026-74962: Site isolation issue in the Networking: Cookies component
- Reporter
- Yaqoub Aldurayhim
- Impact
- moderate
References
#CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-74964: Integer overflow in the Graphics component
- Reporter
- 5up3rh3i
- Impact
- moderate
References
#CVE-2026-74965: Privilege escalation in the Shell Integration component
- Reporter
- Khanh Nguyen
- Impact
- moderate
References
#CVE-2026-74966: Information disclosure in the Form Autofill component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74968: Site isolation issue in the Graphics: WebRender component
- Reporter
- kiyong
- Impact
- moderate
References
#CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component
- Reporter
- Hyeonjun Ahn
- Impact
- moderate
References
#CVE-2026-74970: Site isolation issue in the Graphics component
- Reporter
- Abdulaziz Alasaiqah
- Impact
- moderate
References
#CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component
- Reporter
- avlidienbrunn
- Impact
- moderate
References
#CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component
- Reporter
- Kagami Rosylight
- Impact
- moderate
References
#CVE-2026-74973: Race condition, use-after-free in the Graphics component
- Reporter
- r00tdaddy
- Impact
- moderate
References
#CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- moderate
References
#CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component
- Reporter
- anbu
- Impact
- low
References
#CVE-2026-74977: Integer overflow in the Graphics component
- Reporter
- Vladimir Meier
- Impact
- low
References
#CVE-2026-74978: Clickjacking issue in the Widget component
- Reporter
- hafidzaulia28
- Impact
- low
References
#CVE-2026-74979: Mitigation bypass in the Add-ons Manager component
- Reporter
- Tomoya Nakanishi
- Impact
- low
References
#CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74982: Denial-of-service in the Widget component
- Reporter
- Riski Muhammad Ivan
- Impact
- low
References
#CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74984: Race condition in the JavaScript Engine component
- Reporter
- Amy Burnett of OpenAI
- Impact
- low
References
#CVE-2026-74985: Privilege escalation in the Enterprise Policies component
- Reporter
- The Mozilla Fuzzing Team
- Impact
- low
References
#CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component
- Reporter
- 5up3rh3i
- Impact
- low
References
#CVE-2026-74987: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Reporter
- Nicolas Silva, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
- High Severity internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Moderate Severity internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Low Severity internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
#CVE-2026-74988: Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154
- Reporter
- Gabriele Svelto, Tom Ritter, Tom Schuster and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-74989: Internally found bugs fixed in Thunderbird 154
- Reporter
- Christian Holler, Ryan Hunt, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- moderate
Description
Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.
References
#CVE-2026-74990: Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154
- Reporter
- Christian Holler, Jan de Mooij, Tom Ritter and the Mozilla Fuzzing Team
- Impact
- high
Description
Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited.