CVE-2025-10528: Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component
Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Other sources
This vulnerability affects Firefox < 143 and Firefox ESR < 140.3.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10528?
CVE-2025-10528 is classified as a moderate severity vulnerability affecting certain versions of Firefox and Thunderbird.
How do I fix CVE-2025-10528?
To fix CVE-2025-10528, upgrade to Firefox 143 or Firefox ESR 140.3 or later versions.
What software is affected by CVE-2025-10528?
CVE-2025-10528 affects Mozilla Firefox versions below 143, Firefox ESR versions below 140.3, and Thunderbird versions below 143.
Is there a workaround for CVE-2025-10528?
There are no known workarounds for CVE-2025-10528; the recommended action is to update to the latest versions.
When was CVE-2025-10528 disclosed?
CVE-2025-10528 was disclosed as part of Mozilla’s routine security updates, highlighting vulnerabilities in their products.