Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Mfsa2025 81 | — | Upgrade to Mozilla Firefox version 144.0Upgrade to the latest version of Mozilla Firefox | Oct 15, 2025 | Oct 14, 2025 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 144.0Upgrade to the latest version of Mozilla Thunderbird | Oct 15, 2025 | Oct 14, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub