CVE-2025-13023: Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component
Published Nov 11, 2025
·Updated
Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunderbird 145.
Affected Software
4 affected componentsFixes available
Mozilla Firefox<145
Mozilla Firefox<145
145
Mozilla Thunderbird<145
145
Mozilla Firefox<145.0
Event History
Nov 11, 2025
CVE Published
via Mozilla·12:00 AM
Data Sourced
via Mozilla·12:00 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 13, 2025
Updated
via Mozilla·12:00 AM
Affected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-13023?
CVE-2025-13023 has a severity rating that indicates a significant risk of sandbox escape in affected Firefox versions.
2
How do I fix CVE-2025-13023?
To fix CVE-2025-13023, you should upgrade to Mozilla Firefox version 145 or later.
3
What versions of Firefox are affected by CVE-2025-13023?
CVE-2025-13023 affects all Firefox versions prior to version 145.
4
What is the impact of CVE-2025-13023?
The impact of CVE-2025-13023 allows for a sandbox escape, potentially leading to unauthorized access to system resources.
5
How was CVE-2025-13023 discovered?
CVE-2025-13023 was discovered due to incorrect boundary conditions in the Graphics: WebGPU component.