CVE-2020-12419: Use After Free
Last updated 25 August 2025
Other sources
When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a potentially exploitable crash.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2020-12419?
The severity of CVE-2020-12419 is critical.
Which software versions are affected by CVE-2020-12419?
Firefox ESR < 68.10, Firefox < 78, and Thunderbird < 68.10 are affected by CVE-2020-12419.
What is the vulnerability description of CVE-2020-12419?
CVE-2020-12419 is a use-after-free vulnerability in the parent process of Firefox and Thunderbird, which could lead to memory corruption and potentially exploitable crashes.
How can I fix CVE-2020-12419?
To fix CVE-2020-12419, update your Firefox or Thunderbird to version 78.0.1 or later.
Where can I find more information about CVE-2020-12419?
You can find more information about CVE-2020-12419 in the following references: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1643874), [Mozilla Security Advisories](https://www.mozilla.org/en-US/security/advisories/mfsa2020-24/).