Skip to content
ThreatCluster

Multiple CSP and Network Vulnerabilities Affect Firefox and Thunderbird Users

First seen 18 Feb 2026, 11:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Two vulnerabilities have been identified affecting Firefox and Thunderbird. CVE-2024-6612 allows CSP violations to generate links in the console, leading to DNS prefetching and potential information leakage, impacting Firefox and Thunderbird versions below 128. CVE-2024-4773 permits prior content to remain visible during network errors, which could be exploited to spoof websites, affecting Firefox versions below 126.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2024-05-14
CVE-2024-4773 published
2024-07-09
CVE-2024-6612 published
2026-02-18
Information published about CVE-2024-6612
2026-02-18
Information published about CVE-2024-4773

More articles in this cluster (2)

Following this threat?

Track CVE-2024-4773 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed