A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox escape. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird < 128.10.
2025-04-29T14:15:35.003
2025-11-03T20:19:10.103
Modified
CVSSv3.1: 9.1 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | < 115.23 | Yes |
| Application | mozilla | firefox | < 138.0 | Yes |
| Application | mozilla | firefox | < 128.10 | Yes |
| Application | mozilla | thunderbird | < 128.10.0 | Yes |
| Application | mozilla | thunderbird | < 138.0 | Yes |