CVE-2022-46872: High severity thunderbird vulnerability
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>This bug only affects Thunderbird for Linux. Other operating systems are unaffected.. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Other sources
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.This bug only affects Firefox for Linux. Other operating systems are unaffected.
— Mozilla
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.This bug only affects Thunderbird for Linux. Other operating systems are unaffected.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-46872?
CVE-2022-46872 is a vulnerability that allows an attacker who compromised a content process to partially escape the sandbox and read arbitrary files via clipboard-related IPC messages.
Which operating systems are affected by CVE-2022-46872?
This vulnerability only affects Thunderbird for Linux. Other operating systems are unaffected.
Which versions of Thunderbird and Firefox ESR are affected by CVE-2022-46872?
Thunderbird versions up to and excluding 102.6 and Firefox ESR versions up to and excluding 102.6 are affected.
Which versions of Firefox are affected by CVE-2022-46872?
Firefox versions up to and excluding 108.0 are affected.
What is the severity of CVE-2022-46872?
CVE-2022-46872 has a severity rating of 8.6 (High).