Impact
The advisory details internally found bugs in Thunderbird ESR 153.0 and Thunderbird 153. These bugs exhibited memory corruption or other security‑relevant defects, and the developers believe that with sufficient effort some could be exploited. While the precise exploitation path is not disclosed, the potential for memory corruption or a crash remains, indicating a high‑risk flaw.
Affected Systems
Mozilla's Thunderbird email client is affected, specifically the ESR 153.0 branch and the regular Thunderbird 153 release. Additionally, Mozilla's Firefox browser is impacted, with the ESR 153.1 and 154 releases containing the fix. Users running these versions on any platform face the risk. The updates that were applied, Thunderbird 154 and ESR 153.1, contain the fixes, so systems that have not upgraded remain vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a very high severity. The EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Based on the description, it is inferred that the bugs could lead to memory corruption, but the advisory does not mention a publicly available exploit, so the likelihood of exploitation remains uncertain. No publicly disclosed proof‑of‑concept has been reported, which implies that exploitation risk is low but not zero.
OpenCVE Enrichment