Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.
2025-04-29T14:15:34.913
2025-05-09T19:33:39.363
Analyzed
CVSSv3.1: 5.9 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mozilla | firefox | < 115.23 | Yes |
Application | mozilla | firefox | < 138.0 | Yes |
Application | mozilla | firefox | < 128.10 | Yes |
Application | mozilla | thunderbird | < 128.10.0 | Yes |
Application | mozilla | thunderbird | < 138.0 | Yes |