CVE-2025-1010: Use-after-free in Custom Highlight
An attacker could have caused a use-after-free via the Custom Highlight API, leading to a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1010?
CVE-2025-1010 is classified as a high-severity vulnerability due to its potential for exploitation via a use-after-free in the Custom Highlight API.
How do I fix CVE-2025-1010?
To remediate CVE-2025-1010, update Firefox to version 135, Firefox ESR to version 115.20, or Thunderbird to version 128.7 or later.
Which versions are affected by CVE-2025-1010?
The affected versions of Mozilla products include Firefox versions prior to 135, Thunderbird versions prior to 135, and Firefox ESR versions prior to 115.20.
What could an attacker achieve by exploiting CVE-2025-1010?
An attacker exploiting CVE-2025-1010 could potentially cause a crash in the affected application, leading to disruptive service and possible further attacks.
Is there a workaround available for CVE-2025-1010?
There are no known workarounds for CVE-2025-1010, making it essential to update to the latest secure versions of the affected applications.