Official source evidencewww.mozilla.orgVersioned article
Official source article · www.mozilla.org

Security Vulnerabilities fixed in Thunderbird 153.2 — Mozilla

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publisherwww.mozilla.org
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 20:28 UTC
Linked CVEs29

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-84639Uninitialized memory in MIME parsing
  • CVE-2026-84130Information disclosure in the Graphics: WebGPU component
  • CVE-2026-84132Information disclosure in the Networking: HTTP component
  • CVE-2026-84133Site isolation issue in the DOM: Push Subscriptions component
  • CVE-2026-84134Other issue in the Profile Backup component
  • CVE-2026-84136Other issue in the DOM: Navigation component
  • CVE-2026-84137Spoofing issue in the DOM: Core & HTML component
  • CVE-2026-84139Clickjacking issue in the DOM: Events component
  • CVE-2026-84140Site isolation issue in the DOM: Navigation component
  • CVE-2026-84141Integer overflow in the Graphics: ImageLib component
  • CVE-2026-84143Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
  • CVE-2026-84144Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2
  • CVE-2026-84642Allowed UNC hostnames for attachments interpreted as a regular expression
  • CVE-2026-84637Calendar invitation attachments could launch local executables
  • CVE-2026-84640One byte overflow read in mail parser
  • CVE-2026-84641Information disclosure due to malicious IMAP server response
  • CVE-2026-84129Site isolation issue in the DOM: Navigation component
  • CVE-2026-84145Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15
  • CVE-2026-84123Privilege escalation due to use-after-free in the Graphics: WebGPU component
  • CVE-2026-84121Sandbox escape due to use-after-free in the DOM: Security component
  • CVE-2026-84119Sandbox escape due to use-after-free in the DOM: Navigation component
  • CVE-2026-84131Privilege escalation due to invalid pointer in the Graphics component
  • CVE-2026-74952Privilege escalation in the Application Update component
  • CVE-2026-84125Use-after-free in the DOM: Core & HTML component
  • CVE-2026-84124Use-after-free in the DOM: Core & HTML component
  • CVE-2026-84122Use-after-free in the Audio/Video component
  • CVE-2026-84118Use-after-free in the JavaScript: GC component
  • CVE-2026-84120Use-after-free in the Audio/Video component
  • CVE-2026-75874Sandbox escape in the Remote Settings Client component

Source and provenance

Original title: Security Vulnerabilities fixed in Thunderbird 153.2 — Mozilla. Captured 26 Sept 2026, 20:28 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗