First published: Tue Apr 01 2025(Updated: )
Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <137 | 137 |
Thunderbird | <137 | 137 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2025-3034 is considered to have a high severity due to potential memory corruption and arbitrary code execution risks.
To fix CVE-2025-3034, update to the latest versions of Firefox or Thunderbird, specifically version 137 or higher.
CVE-2025-3034 affects Firefox versions prior to 137 and Thunderbird versions prior to 137.
The risks include possible exploitation through memory corruption that could lead to arbitrary code execution.
CVE-2025-3034 was disclosed in the security advisories published by Mozilla.