We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 140.13, and Thunderbird 140.13.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade thunderbird | Aug 5, 2026 | Aug 4, 2026 |
| Debian | — | Upgrade firefox-esrUpgrade thunderbird | Jul 23, 2026 | Jul 23, 2026 |
| Mfsa2026 67 | — | Upgrade to Mozilla Firefox version 152.0.6 | Jul 14, 2026 | Jul 14, 2026 |
| Mfsa2026 70 | — | Upgrade to the latest version of Mozilla FirefoxUpgrade to Mozilla Firefox ESR version 140.13 | Jul 21, 2026 | Jul 21, 2026 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 140.13Upgrade to the latest version of Mozilla Thunderbird | Jul 21, 2026 | Jul 21, 2026 |
| Redhat_linux | — | No solution existsUpgrade firefox-debugsourceUpgrade thunderbird-debuginfoUpgrade thunderbird-debugsourceUpgrade firefoxUpgrade firefox-debuginfoUpgrade firefox-x11Upgrade thunderbird | Jul 27, 2026 | Jul 14, 2026 |
| Rocky_linux | — | Upgrade firefoxUpgrade firefox-x11Upgrade thunderbirdUpgrade firefox-debugsourceUpgrade thunderbird-debugsourceUpgrade thunderbird-debuginfoUpgrade firefox-debuginfo | Jul 31, 2026 | Jul 29, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub