CVE-2025-11709: Out of bounds read/write in a privileged process triggered by WebGL textures
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.29 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11709?
CVE-2025-11709 is marked as a high severity vulnerability due to its ability to trigger out of bounds reads and writes.
How do I fix CVE-2025-11709?
To fix CVE-2025-11709, update Mozilla Firefox to version 144, Firefox ESR to version 115.29 or 140.4, and Thunderbird to version 144 or 140.4.
What types of software are affected by CVE-2025-11709?
CVE-2025-11709 affects Mozilla Firefox, Mozilla Firefox ESR, and Mozilla Thunderbird versions prior to the specified patched versions.
What causes the vulnerability CVE-2025-11709?
CVE-2025-11709 is caused by a compromised web process manipulating WebGL textures to trigger out of bounds memory access.
Can CVE-2025-11709 lead to further exploitation?
Yes, CVE-2025-11709 can potentially lead to privilege escalation if an attacker successfully exploits it.