CVE-2025-4920: Critical severity firefox vulnerability
Published May 17, 2025
·Updated
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object.
Other sources
Rejected reason: Duplicate of CVE-2025-4918
— NVD
Affected Software
4 affected componentsFixes available
Mozilla Firefox<138.0.4
Mozilla Firefox ESR<128.10.1
Mozilla Firefox<138.0.4
138.0.4
Mozilla Firefox ESR<128.10.1
128.10.1
Event History
May 17, 2025
CVE Published
via Mozilla·12:00 AM
CVE Published
via MITRE·09:07 PM
Rejected
via MITRE·09:07 PM
Data Sourced
via NVD·10:15 PM
Description
May 18, 2025
Rejected
via MITRE·07:21 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-4920?
CVE-2025-4920 is classified as a high-severity vulnerability that can lead to out-of-bounds read or write on JavaScript Promise objects.
2
How do I fix CVE-2025-4920?
To fix CVE-2025-4920, update Firefox to version 138.0.4 or Firefox ESR to version 128.10.1.
3
What versions of Firefox are affected by CVE-2025-4920?
CVE-2025-4920 affects all Firefox versions prior to 138.0.4 and Firefox ESR versions prior to 128.10.1.
4
What type of attack does CVE-2025-4920 facilitate?
CVE-2025-4920 facilitates potential out-of-bounds read or write attacks through a vulnerable JavaScript Promise object.
5
Is CVE-2025-4920 present in the latest Firefox release?
No, CVE-2025-4920 is not present in the latest Firefox release starting from version 138.0.4.