CVE-2025-11708: Use-after-free in MediaTrackGraphImpl::GetInstance()
Use-after-free in MediaTrackGraphImpl::GetInstance()
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Mozilla Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Mozilla Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11708?
CVE-2025-11708 is classified as a use-after-free vulnerability which can lead to potential security risks like arbitrary code execution.
How do I fix CVE-2025-11708?
To fix CVE-2025-11708, update Firefox and Thunderbird to version 144 or Thunderbird ESR to version 140.4.
What versions of Firefox are affected by CVE-2025-11708?
CVE-2025-11708 affects Firefox versions below 144.
What versions of Thunderbird are affected by CVE-2025-11708?
CVE-2025-11708 affects Thunderbird versions below 144 and Thunderbird ESR versions below 140.4.
How can CVE-2025-11708 impact my system?
CVE-2025-11708 can lead to crashes or exploit attempts which may compromise system security and lead to unauthorized access.