CVE-2025-4082Medium· 5.9▾ SunlitModification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Thunderbird for macOS. Other versions of T…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.
firefox < 115.23firefox < 138.0firefox >= 128.0, < 128.10thunderbird < 128.10.0thunderbird < 138.0Upgrade past the affected range:
firefox 128.10thunderbird 138.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-2771Critical· 9.8Undefined behavior in the DOM: Core & HTML component
CVE-2026-92072High· 8.0Incorrect boundary conditions in the Safe Browsing component
CVE-2026-8092High· 8.1Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1
CVE-2026-12298Medium· 5.4Memory safety bug fixed in Firefox 152
CVE-2026-96869Medium· 4.3Information disclosure in the Networking component
CVE-2026-100832High· 8.8Use-after-free in the Graphics: Canvas2D component