Back

HIGH

Mozilla: Attachment files saved to disk on macOS could be executed without warning

Published Dec 22, 2022

Description

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mozilla
Published Dec 22, 2022
Updated Apr 15, 2025
Reserved Sep 7, 2022
CISA Vulnrichment
Updated Apr 15, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 20, 2022