Mozilla · Thunderbird · CVE-2024-4767
**Name of the Vulnerable Software and Affected Versions**
Firefox versions prior to 126
Firefox ESR versions prior to 115.11
Thunderbird versions prior to 115.11
**Description**
The issue is related to the improper deletion of IndexedDB files when the `browser.privatebrowsing.autostart` preference is enabled and the window is closed. This preference is disabled by default in Firefox. The vulnerability can be exploited by a remote attacker to gain access to confidential data due to errors in data type conversion when the private browsing mode autostart is enabled.
**Recommendations**
For Firefox versions prior to 126, update to version 126 or later to resolve the issue.
For Firefox ESR versions prior to 115.11, update to version 115.11 or later to resolve the issue.
For Thunderbird versions prior to 115.11, update to version 115.11 or later to resolve the issue.