CVE-2025-49709: Memory corruption in canvas surfaces
Published Jun 10, 2025
·Updated
Certain canvas operations could have lead to memory corruption.
Affected Software
2 affected componentsFixes available
Mozilla Firefox<139.0.4
139.0.4
Mozilla Firefox<139.0.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 139.0.4
Event History
Jun 10, 2025
CVE Published
via Mozilla·12:00 AM
Jun 11, 2025
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-49709?
CVE-2025-49709 is rated as a critical vulnerability due to its potential for memory corruption.
2
How do I fix CVE-2025-49709?
To mitigate CVE-2025-49709, upgrade Firefox to version 139.0.4 or later.
3
What versions of Firefox are affected by CVE-2025-49709?
CVE-2025-49709 affects all Firefox versions prior to 139.0.4.
4
Can CVE-2025-49709 be exploited remotely?
Yes, CVE-2025-49709 could potentially be exploited remotely if certain conditions are met.
5
What specific operations are associated with CVE-2025-49709?
CVE-2025-49709 is linked to certain canvas operations that may lead to memory corruption.