CVE-2020-12405: Race Condition
Last updated 25 August 2025
Other sources
When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2020-12405?
CVE-2020-12405 is a vulnerability that can occur in Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9 when browsing a malicious page, leading to a potentially exploitable crash due to a race condition in the SharedWorkerService.
How severe is CVE-2020-12405?
CVE-2020-12405 has a severity rating of 5.3 (high).
Which software versions are affected by CVE-2020-12405?
Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9 are affected by CVE-2020-12405.
How can I fix CVE-2020-12405?
To fix CVE-2020-12405, update Thunderbird to 68.9.0 or later, update Firefox to 77.0.1 or later, and update Firefox ESR to 68.9.0 or later.
Where can I find more information about CVE-2020-12405?
You can find more information about CVE-2020-12405 at the following references: [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1631618), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2020-22/), [Mozilla Security Advisories](https://www.mozilla.org/security/advisories/mfsa2020-20/).