CVE-2025-5262: Mozilla Thunderbird

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.

Affected products

  • Mozilla Thunderbird: before 128.11.0 (fixed in 128.11.0); before 139.0 (fixed in 139.0)

Published 2025-05-27. Last modified 2026-06-17.