CVE-2025-4093: Memory safety bug fixed in Firefox ESR 128.10 and Thunderbird 128.10
Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and we presume that with enough effort this could have been exploited to run arbitrary code.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4093?
CVE-2025-4093 has the potential for high severity due to the presence of memory corruption that could allow for arbitrary code execution.
How do I fix CVE-2025-4093?
To fix CVE-2025-4093, update Firefox ESR or Thunderbird ESR to version 128.10 or later.
Which versions are affected by CVE-2025-4093?
CVE-2025-4093 affects Firefox ESR versions below 128.10 and Thunderbird ESR versions below 128.10.
What are the consequences of CVE-2025-4093 if left unpatched?
If CVE-2025-4093 is left unpatched, it could potentially be exploited to execute arbitrary code on affected systems.
Is CVE-2025-4093 relevant to all users of Firefox and Thunderbird?
CVE-2025-4093 specifically affects users of Firefox ESR and Thunderbird ESR versions prior to 128.10.