CVE-2025-4082: WebGL shader attribute memory corruption in Thunderbird for macOS
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.. This vulnerability was fixed in Firefox 138, Firefox ESR 128.10, Firefox ESR 115.23, Thunderbird 138, and Thunderbird 128.10.
Other sources
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.
— Mozilla
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4082?
CVE-2025-4082 has been assessed with a high severity level due to potential privilege escalation risks.
How do I fix CVE-2025-4082?
To fix CVE-2025-4082, update to Firefox or Thunderbird versions 138 or later, or Firefox ESR 129 or later.
Which versions of Firefox are affected by CVE-2025-4082?
CVE-2025-4082 affects Firefox versions below 138 on macOS.
Does CVE-2025-4082 affect Firefox on other operating systems?
No, CVE-2025-4082 specifically affects Firefox for macOS only.
Can CVE-2025-4082 be exploited without user interaction?
Exploitation of CVE-2025-4082 may require the victim to visit a malicious webpage, indicating some user interaction is typically necessary.