Impact
Internally discovered bugs in Thunderbird 153 caused memory corruption or other security‑relevant defects, and the vendor presumes that, with sufficient effort, these could have been exploited to achieve arbitrary code execution. The vulnerability was addressed in Firefox 154 and Thunderbird 154.
Affected Systems
Mozilla Firefox 153 and Mozilla Thunderbird 153 are affected. These vulnerabilities were fixed in version 154 of each product. Users of Firefox 154 or later, or Thunderbird 154 or later, are not impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates a very high severity. The EPSS score of less than 1% implies a low likelihood of exploitation in the wild, though a dedicated attacker could still target these flaws. The vulnerability involves memory corruption; the likely attack vector is input‑based, such as malicious email attachments, web content, or extensions, but the exact method is not documented. The likely attack vector is inferred from the description. The flaw is not listed in the CISA KEV catalog.
OpenCVE Enrichment