CVE-2025-11710: Cross-process information leaked due to malicious IPC messages
A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks of its memory to the compromised process.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.29 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11710?
CVE-2025-11710 has been classified as a critical severity vulnerability due to the potential for memory disclosure.
How do I fix CVE-2025-11710?
To fix CVE-2025-11710, update your Mozilla Firefox or Thunderbird to the latest version provided by Mozilla.
What products are affected by CVE-2025-11710?
CVE-2025-11710 affects Mozilla Firefox ESR up to version 115.29, Mozilla Thunderbird up to version 140.4, and standard Mozilla Firefox up to version 144.
What type of attack is associated with CVE-2025-11710?
CVE-2025-11710 is associated with attacks that exploit IPC messages in a web process to leak memory from the privileged browser process.
Is user intervention required for CVE-2025-11710?
Yes, user intervention is required to apply the necessary updates to mitigate CVE-2025-11710.