CVE-2025-11711 | Mozilla Thunderbird up to 143 Javascript Object sensitive data storage in improperly locked memory (Nessus ID 270392 / WID-SEC-2025-2275)
A vulnerability marked as problematic has been reported in Mozilla Thunderbird up to 143. Affected by this issue is some unknown functionality of the component Javascript Object Handler. The manipulation leads to sensitive data storage in improperly locked memory.
This vulnerability is documented as CVE-2025-11711. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.