Skip to finding
important · Zero-click — Thunderbird

Thunderbird fixed a MIME path that uses uninitialized memory, but receipt-only triggering remains unknown.

Affects

Mozilla Thunderbird, a desktop email and calendar client on Windows, macOS and Linux.

A crafted MIME body can enter the affected error path. Public material does not say whether background synchronization is enough, whether preview or opening is required, or whether the stale value controls a security-sensitive operation.

Detail and 3 sources

Mozilla shipped fixes across release and ESR channels on September 1. Until trigger timing and the stale value’s consumer are known, this is a memory-safety primitive rather than an established receipt-only compromise.

Chain to watch
Send a crafted email containing a MIME body that reaches the affected error path.→↓Determine whether synchronization, preview, or explicit opening invokes the path.→↓Identify whether the uninitialized value reaches a pointer, length, or another security-sensitive operation.→↓Whether synchronization alone triggers the path and whether the stale value has an exploitable consumer.
Unverified chainObtain the restricted testcase or run malformed MIME bodies under MemorySanitizer while testing synchronization, preview, and explicit-open paths separately.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 2, 2026