First published: Tue Apr 01 2025(Updated: )
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <137 | 137 |
Thunderbird | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-3031 is considered a moderate severity vulnerability that allows an attacker to read sensitive data from the stack.
To fix CVE-2025-3031, upgrade Firefox or Thunderbird to version 137 or later.
CVE-2025-3031 affects Firefox versions earlier than 137 and Thunderbird versions earlier than 137.
An attacker can exploit CVE-2025-3031 to read 32 bits of values that are spilled onto the stack in JIT compiled functions.
There is no known workaround for CVE-2025-3031, so updating to the latest versions is recommended.