First published: Tue Apr 29 2025(Updated: )
Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Thunderbird < 138, and Thunderbird ESR < 128.10.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Firefox | <138 | |
Firefox ESR | <128.10 | |
Thunderbird | <138 | |
Mozilla Thunderbird | <128.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-4091 has been classified as a memory safety vulnerability that could potentially allow the execution of arbitrary code.
To resolve CVE-2025-4091, update Firefox to version 138 or newer, and Thunderbird to version 139 or newer.
CVE-2025-4091 affects Mozilla Firefox versions below 138, Firefox ESR versions below 128.10, and Thunderbird versions below 138.
CVE-2025-4091 is associated with memory safety bugs that exhibit evidence of memory corruption.
While CVE-2025-4091 shows potential for exploitation, it requires significant effort to achieve arbitrary code execution.