CVE-2025-4921: Critical severity firefox esr vulnerability
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes.
Other sources
Rejected reason: Duplicate of CVE-2025-4919
— NVD
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4921?
CVE-2025-4921 has been classified as a severe vulnerability due to its potential to allow attackers to perform out-of-bounds reads or writes.
How do I fix CVE-2025-4921?
To fix CVE-2025-4921, upgrade to the remediated versions of Firefox ESR 128.10.1 or Firefox 138.0.4 or later.
What kind of attacks can CVE-2025-4921 facilitate?
CVE-2025-4921 can facilitate attacks that exploit out-of-bounds reads or writes on JavaScript objects, potentially leading to information disclosure or application crashes.
Which versions of Firefox are affected by CVE-2025-4921?
CVE-2025-4921 affects Firefox ESR versions up to 128.10.1 and Firefox versions up to 138.0.4.
Is CVE-2025-4921 specific to any particular operating system?
CVE-2025-4921 is not specific to a particular operating system but affects the specified versions of Firefox on all supported platforms.