First published: Tue Apr 29 2025(Updated: )
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <138 | |
Firefox ESR | <128.10<115.23 | |
Thunderbird | <138 | |
Mozilla Thunderbird | <128.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4082 has been assessed with a high severity level due to potential privilege escalation risks.
To fix CVE-2025-4082, update to Firefox or Thunderbird versions 138 or later, or Firefox ESR 129 or later.
CVE-2025-4082 affects Firefox versions below 138 on macOS.
No, CVE-2025-4082 specifically affects Firefox for macOS only.
Exploitation of CVE-2025-4082 may require the victim to visit a malicious webpage, indicating some user interaction is typically necessary.