CVE-2025-13016: Incorrect boundary conditions in the JavaScript: WebAssembly component
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.
Other sources
Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunderbird 145, and Thunderbird 140.5.
— MITRE
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13016?
CVE-2025-13016 has a high severity rating due to incorrect boundary conditions that may lead to exploitation in affected versions.
How do I fix CVE-2025-13016?
To fix CVE-2025-13016, upgrade to Firefox version 145 or Firefox ESR version 140.5 or later.
Which versions of Firefox are affected by CVE-2025-13016?
CVE-2025-13016 affects Firefox versions earlier than 145 and Firefox ESR versions earlier than 140.5.
What are the potential impacts of CVE-2025-13016?
Exploitation of CVE-2025-13016 could potentially lead to remote code execution or unauthorized access.
Is there a workaround for CVE-2025-13016?
There are no confirmed workarounds for CVE-2025-13016; the recommended action is to update to a patched version.