CVE-2025-5268: Memory safety bugs fixed in Firefox 139, Thunderbird 139, Firefox ESR 128.11, and Thunderbird 128.11
Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-5268?
CVE-2025-5268 is considered a high severity vulnerability due to the potential for memory corruption that could allow arbitrary code execution.
How do I fix CVE-2025-5268?
To fix CVE-2025-5268, update your Mozilla Firefox or Thunderbird to version 139 or Mozilla Firefox ESR to version 128.11.
What versions are affected by CVE-2025-5268?
CVE-2025-5268 affects Mozilla Firefox versions up to 138, Thunderbird versions up to 138, and Firefox ESR versions up to 128.10.
What types of software are impacted by CVE-2025-5268?
CVE-2025-5268 impacts Mozilla Firefox, Mozilla Thunderbird, and Mozilla Firefox ESR.
Are there any known exploits for CVE-2025-5268?
While there is no confirmation of active exploits, the nature of CVE-2025-5268 indicates that it could potentially be exploited with sufficient technical effort.