CVE-2025-11715: Memory safety bugs fixed in Firefox ESR 140.4, Thunderbird ESR 140.4, Firefox 144 and Thunderbird 144
Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 144 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.4 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 144 - Upgrade
Upgrade
Thunderbird ESRto a version that resolves this vulnerability.Fixed in 140.4
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11715?
CVE-2025-11715 has a high severity rating due to evidence of memory corruption that could potentially be exploited to run arbitrary code.
How do I fix CVE-2025-11715?
To fix CVE-2025-11715, update affected Mozilla software to the latest versions: Thunderbird and Firefox ESR to 140.4, and regular Firefox and Thunderbird to 144.
Which versions are affected by CVE-2025-11715?
CVE-2025-11715 affects Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143, and Thunderbird 143.
What are memory safety bugs in the context of CVE-2025-11715?
Memory safety bugs refer to vulnerabilities that can lead to memory corruption, potentially allowing attackers to exploit these flaws.
Is CVE-2025-11715 actively being exploited?
While some of the memory safety bugs in CVE-2025-11715 show evidence of possible exploitation, there is no confirmed active exploitation reported.