CVE-2025-10537: Memory safety bugs fixed in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143
Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-10537?
CVE-2025-10537 is considered a moderate severity vulnerability due to potential memory corruption and the risk of arbitrary code execution.
How do I fix CVE-2025-10537?
To fix CVE-2025-10537, update Firefox and Thunderbird to the latest versions, specifically beyond Firefox 143 and Thunderbird 143.
Which versions are affected by CVE-2025-10537?
CVE-2025-10537 affects Firefox versions up to 143, Firefox ESR up to 140.3, Thunderbird up to 143, and Thunderbird ESR up to 140.3.
What types of software are impacted by CVE-2025-10537?
CVE-2025-10537 impacts Mozilla Firefox, Firefox ESR, Mozilla Thunderbird, and Thunderbird ESR.
Is exploiting CVE-2025-10537 easy?
Exploiting CVE-2025-10537 may be possible with sufficient effort due to the memory safety bugs present, but it requires technical expertise.