CVE-2025-11711: Some non-writable Object properties could be modified
There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.29 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.29 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11711?
The severity of CVE-2025-11711 can be classified as high due to its potential impact on the integrity of JavaScript Object properties.
How do I fix CVE-2025-11711?
To fix CVE-2025-11711, upgrade to Firefox version 144, Firefox ESR version 115.29, or Thunderbird version 140.4 or later.
Which versions of Firefox are affected by CVE-2025-11711?
Firefox versions lower than 144 are affected by CVE-2025-11711.
Does CVE-2025-11711 affect Thunderbird?
Yes, CVE-2025-11711 affects Thunderbird versions lower than 144.
What platforms are impacted by CVE-2025-11711?
CVE-2025-11711 impacts platforms running affected versions of Firefox and Thunderbird on desktop.