CVE-2025-8028: Large branch table could lead to truncated instruction
On arm64, a WASM brtable instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability affects Firefox < 141, Firefox ESR < 115.26, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
Other sources
On arm64, a WASM brtable instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
— MITRE
On arm64, a WASM brtable instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address.
— Mozilla
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 128.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.26 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8028?
CVE-2025-8028 is considered to have a moderate severity due to potential computational errors caused by the truncation of branch addresses.
How do I fix CVE-2025-8028?
To fix CVE-2025-8028, update your Mozilla Firefox or Firefox ESR browser to at least version 115.26 or the latest available version.
Which versions of Firefox are affected by CVE-2025-8028?
CVE-2025-8028 affects Firefox versions up to 141 and Firefox ESR versions up to 115.26, including 128.13 and 140.1.
What impact does CVE-2025-8028 have on users?
Users affected by CVE-2025-8028 may experience incorrect computation of branch addresses during the execution of specific WASM instructions.
Is CVE-2025-8028 a browser-specific vulnerability?
Yes, CVE-2025-8028 specifically affects the Mozilla Firefox and Firefox ESR browsers on arm64 architecture.