CVE-2025-4091: Memory safety bugs fixed in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4091?
CVE-2025-4091 has been classified as a memory safety vulnerability that could potentially allow the execution of arbitrary code.
How do I fix CVE-2025-4091?
To resolve CVE-2025-4091, update Firefox to version 138 or newer, and Thunderbird to version 139 or newer.
What software is affected by CVE-2025-4091?
CVE-2025-4091 affects Mozilla Firefox versions below 138, Firefox ESR versions below 128.10, and Thunderbird versions below 138.
What types of bugs are associated with CVE-2025-4091?
CVE-2025-4091 is associated with memory safety bugs that exhibit evidence of memory corruption.
Can CVE-2025-4091 be exploited?
While CVE-2025-4091 shows potential for exploitation, it requires significant effort to achieve arbitrary code execution.