CVE-2025-11719: Use-after-free caused by the native messaging web extension API on Windows
Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.
Other sources
Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11719?
CVE-2025-11719 is classified as a high severity vulnerability due to the potential for use-after-free memory corruption leading to application crashes.
How do I fix CVE-2025-11719?
To mitigate CVE-2025-11719, update to Mozilla Firefox or Thunderbird version 144 or later.
Which versions of Firefox are affected by CVE-2025-11719?
CVE-2025-11719 affects all versions of Mozilla Firefox prior to version 144.
Which versions of Thunderbird are affected by CVE-2025-11719?
CVE-2025-11719 affects all versions of Mozilla Thunderbird prior to version 144.
What systems are impacted by CVE-2025-11719?
CVE-2025-11719 specifically impacts the use of the native messaging API by web extensions on Windows systems.