First published: Tue Apr 01 2025(Updated: )
JavaScript code running while transforming a document with the XSLTProcessor could lead to a use-after-free.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox ESR | <115.22 | 115.22 |
Firefox ESR | <128.9 | 128.9 |
Thunderbird | <137 | 137 |
Mozilla Thunderbird | <128.9 | 128.9 |
Firefox | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2025-3028 is classified as a high severity vulnerability due to the potential for use-after-free conditions in affected Mozilla products.
To address CVE-2025-3028, users should update their Firefox or Thunderbird to the latest versions 115.22, 128.9, or 137 as applicable.
CVE-2025-3028 affects Firefox versions before 137, Firefox ESR versions before 115.22 and 128.9, as well as Thunderbird versions before 137.
CVE-2025-3028 impacts Mozilla Firefox, Firefox ESR, and Thunderbird related products.
There are no recommended workarounds for CVE-2025-3028; updating to the secure versions is the only effective solution.