CVE-2025-10527: Sandbox escape due to use-after-free in the Graphics: Canvas2D component
Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Other sources
This vulnerability affects Firefox < 143 and Firefox ESR < 140.3.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10527?
CVE-2025-10527 has been classified as a high-severity vulnerability in affected versions.
Which versions of Firefox are affected by CVE-2025-10527?
CVE-2025-10527 affects Firefox versions earlier than 143 and Firefox ESR versions earlier than 140.3.
How do I fix CVE-2025-10527?
To fix CVE-2025-10527, upgrade to Firefox 143 or later, or Firefox ESR 140.3 or later.
What types of attacks could exploit CVE-2025-10527?
CVE-2025-10527 could potentially be exploited for unauthorized access or escalation of privileges.
Is there a workaround for CVE-2025-10527?
No official workaround for CVE-2025-10527 is recommended; updating your browser is the best approach.