CVE-2025-4092: Memory safety bugs fixed in Firefox 138 and Thunderbird 138
Published Apr 29, 2025
·Updated
Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
6 affected componentsFixes available
Mozilla Firefox<138
Mozilla Thunderbird<138
Mozilla Thunderbird<138
138
Mozilla Firefox<138
138
Mozilla Firefox<138.0
Mozilla Thunderbird<138.0
Event History
Apr 29, 2025
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·01:13 PM
Data Sourced
via MITRE·01:13 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2025-4092?
CVE-2025-4092 has a high severity due to potential memory corruption leading to arbitrary code execution.
2
How do I fix CVE-2025-4092?
To fix CVE-2025-4092, update Firefox and Thunderbird to version 138 or later.
3
Which versions are affected by CVE-2025-4092?
CVE-2025-4092 affects Firefox versions earlier than 138 and Thunderbird versions earlier than 138.
4
Can CVE-2025-4092 be exploited remotely?
Yes, if successfully exploited, CVE-2025-4092 could allow remote attackers to execute arbitrary code.
5
What are the products affected by CVE-2025-4092?
CVE-2025-4092 affects Mozilla Firefox and Mozilla Thunderbird versions below 138.