MEDIUM 4.3

CVE-2026-12320: Firefox and Thunderbird Password Manager Information Disclosure

A flaw in Firefox and Thunderbird's Password Manager allows sensitive credential information to be disclosed to an attacker under certain conditions. The vulnerability requires user interaction to exploit—an attacker cannot trigger it remotely without the user taking action. The exposure is limited to confidentiality; attackers cannot modify data or cause service disruption. Mozilla has addressed this issue in Firefox 152 and Thunderbird 152.

Source data · NVD / CISA · public domain

CVSS
3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Weaknesses (CWE)
CWE-200
Affected products
2 configuration(s)
Published / Modified
2026-06-16 / 2026-06-17

NVD description (verbatim)

Information disclosure in the Password Manager component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-12320 is an information disclosure vulnerability (CWE-200) affecting the Password Manager component in Mozilla Firefox and Thunderbird. The CVSS 3.1 score of 4.3 (Medium severity) reflects a network-accessible attack vector with low complexity, no privilege requirements, and user interaction needed. The vulnerability results in partial confidentiality loss without integrity or availability impact. The attack surface is unauthenticated and local in scope, meaning the affected system boundaries do not extend beyond the compromised application.

Business impact

If Firefox or Thunderbird users fall victim to this attack, stored passwords and authentication credentials could be exposed, potentially enabling account takeover or unauthorized access to services managed through those credentials. The practical impact is constrained by the requirement for user interaction and the fact that exploitation does not grant persistence or system-level access. Organizations should assess exposure based on whether users rely on these applications' Password Managers for enterprise credential storage—many enterprises restrict this practice and use dedicated password vaults instead.

Affected systems

Mozilla Firefox versions prior to 152 and Mozilla Thunderbird versions prior to 152 are affected. The vulnerability does not impact other browsers or email clients. Users running older versions of either application with an active Password Manager are at risk. Check your installed versions: open Firefox or Thunderbird, navigate to Help > About, and confirm the version number.

Exploitability

Exploitation requires user interaction, preventing fully automated attacks from remote networks. An attacker would need to craft a scenario or malicious content that tricks a user into initiating the vulnerable code path within the Password Manager. Once triggered, the attacker gains read access to stored passwords without authentication. The attack does not require elevated privileges or system-level access, and the barrier to exploitation is moderate—social engineering or a carefully crafted webpage would be necessary rather than zero-click exploitation.

Remediation

Update Firefox to version 152 or later and Thunderbird to version 152 or later. These versions contain the security fix. Verify that automatic updates are enabled in your settings to prevent gap exposure. Organizations managing multiple Firefox or Thunderbird deployments should use centralized deployment tools and group policy to enforce timely patching across the fleet.

Patch guidance

Mozilla released fixes in Firefox 152 and Thunderbird 152. Users can enable automatic updates (default in most configurations) or manually check Help > About [Product Name] to trigger an update check. For enterprise deployments, download the latest versions from mozilla.org and distribute via your software management platform. Test in a pilot group before wide rollout to ensure compatibility with any legacy extensions or policies. No interim workarounds are available; patching is the only remediation.

Detection guidance

Monitor for Firefox and Thunderbird installations running versions below 152 using endpoint inventory or asset management tools. Review browser and email client logs for unusual password decryption or access events if available in your logging infrastructure. Most users will not see obvious signs of exploitation; detection relies on version inventory. Consider deploying browser inventory tools or leveraging SIEM solutions to track installed application versions across your environment.

Why prioritize this

Although rated Medium severity, this vulnerability affects two widely deployed applications. The requirement for user interaction limits urgency, but the exposure of credentials—a critical asset—warrants expedited patching. Organizations heavily dependent on users' Firefox/Thunderbird Password Managers should prioritize within 2–4 weeks. Those using centralized password management can deprioritize slightly without material risk. The lack of KEV listing and absence of active in-the-wild exploitation provide some relief, but the fundamental exposure should not be ignored.

Risk score, explained

The CVSS 3.1 score of 4.3 (Medium) balances multiple factors: network accessibility and low attack complexity increase severity, while mandatory user interaction and limited confidentiality impact reduce it. No integrity or availability damage occurs, further lowering the score. In practice, risk is modulated by whether your users rely on Firefox/Thunderbird for critical credential storage—if they use a dedicated password manager, actual risk is lower; if your organization encourages Password Manager use, risk is higher than the baseline CVSS suggests.

Frequently asked questions

Does this vulnerability affect Chrome, Edge, or Safari?

No. CVE-2026-12320 is specific to Firefox and Thunderbird. Other browsers and email clients are not affected.

Can this vulnerability be exploited without the user clicking or interacting with something?

No. The vulnerability requires user interaction to trigger. An attacker cannot silently extract credentials from a user's machine; they must manipulate the user into invoking the vulnerable code path.

What if I don't use the built-in Password Manager and store passwords elsewhere?

You are not at risk from this vulnerability. If you use a dedicated password manager like Bitwarden, 1Password, or Dashlane, this flaw in Firefox/Thunderbird's Password Manager does not affect you.

Is there a temporary workaround until I can update?

No documented workaround exists. The safest interim step is to disable the Password Manager in Firefox/Thunderbird settings and use an external password manager until you upgrade to version 152 or later.

This analysis is based on information available as of the vulnerability publication date and reflects the CVSS score, affected versions, and remediation guidance released by Mozilla. Security landscape changes may affect risk assessment over time. Verify all patch version numbers and technical details against official vendor advisories before implementing changes. This document is for informational purposes and does not constitute professional security advice for your specific environment. Consult with your security team to determine prioritization based on your organization's threat model and asset inventory. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).