
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-4082 is a high-impact vulnerability discovered in April 2025 affecting Thunderbird for macOS. The vulnerability involves WebGL shader attribute manipulation that could trigger an out-of-bounds read condition. This security flaw specifically impacts Thunderbird versions < 138 and < 128.10 on macOS systems, while other versions of Thunderbird remain unaffected (Mozilla Advisory).
The vulnerability stems from improper handling of WebGL shader attributes in Thunderbird's rendering engine. When specific WebGL shader attributes are modified, it can trigger an out-of-bounds read condition. The vulnerability has been assigned a CVSS 3.1 Base Score of 5.9 (Medium) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N, indicating network accessibility with high attack complexity (NVD).
The vulnerability could lead to privilege escalation when chained with other vulnerabilities. The out-of-bounds read condition could potentially expose sensitive memory contents, making it particularly concerning for systems processing confidential information. The impact is specifically rated as high for macOS users of Thunderbird (Mozilla Advisory).
Mozilla has addressed this vulnerability in Thunderbird 138 and Thunderbird 128.10. Users are strongly advised to update to these versions or later to mitigate the risk. The fix has been implemented in the latest releases of Thunderbird (Mozilla Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."