CVE-2025-10533: Integer overflow in the SVG component
Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird 143, and Thunderbird 140.3.
Other sources
This vulnerability affects Firefox < 143, Firefox ESR < 115.28, and Firefox ESR < 140.3.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10533?
CVE-2025-10533 is classified as a high severity vulnerability that can potentially lead to exploitation in affected versions of Firefox.
How do I fix CVE-2025-10533?
To fix CVE-2025-10533, upgrade your Firefox or Firefox ESR to the latest version that addresses this vulnerability.
Which versions of Firefox are affected by CVE-2025-10533?
CVE-2025-10533 affects Firefox versions prior to 143 and Firefox ESR versions prior to 115.28 and 140.3.
Is there a workaround for CVE-2025-10533 if I cannot upgrade?
Currently, there are no known workarounds for CVE-2025-10533; updating is the recommended solution.
What types of attacks can CVE-2025-10533 facilitate?
CVE-2025-10533 may allow remote code execution or data exposure, making it critical to address promptly.