CVE-2019-17025: High severity Mozilla Firefox vulnerability
Last updated 25 August 2025
Other sources
Mozilla developers Karl Tomlinson, Jason Kratzer, Tyson Smith, Jon Coppeard, and Christian Holler reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.
— Launchpad
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17025?
CVE-2019-17025 is a vulnerability that involves memory safety bugs present in Firefox 71, which could potentially be exploited to run arbitrary code.
Who reported the memory safety bugs in Firefox 71?
The memory safety bugs in Firefox 71 were reported by Mozilla developers Karl Tomlinson, Jason Kratzer, Tyson Smith, Jon Coppeard, and Christian Holler.
What is the severity of CVE-2019-17025?
CVE-2019-17025 has a severity score of 8.8, indicating a high severity.
How can I fix CVE-2019-17025?
To fix CVE-2019-17025, update your Firefox browser to version 72 or higher.
Where can I find more information about CVE-2019-17025?
You can find more information about CVE-2019-17025 in the bugzilla.mozilla.org and mozilla.org websites.