CVE-2025-13027: Memory safety bugs fixed in Firefox 145 and Thunderbird 145
Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13027?
CVE-2025-13027 is classified as a high severity vulnerability due to the potential for memory corruption and arbitrary code execution.
How do I fix CVE-2025-13027?
To fix CVE-2025-13027, upgrade to Mozilla Firefox and Thunderbird version 145 or later.
Which versions of software are affected by CVE-2025-13027?
CVE-2025-13027 affects Mozilla Firefox and Thunderbird versions prior to 145.
Can CVE-2025-13027 be exploited remotely?
While not confirmed, the evidence of memory corruption in CVE-2025-13027 suggests it could be exploited remotely with sufficient effort.
What types of vulnerabilities are present in CVE-2025-13027?
CVE-2025-13027 includes memory safety bugs that could lead to memory corruption.