CVE-2025-8033: Incorrect JavaScript state machine for generators
The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 115.26 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 128.13 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 140.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 141 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.26 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 140.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 141 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 128.13 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 140.1
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8033?
CVE-2025-8033 is classified as a moderate severity vulnerability due to the potential for a null pointer dereference leading to application crashes.
How do I fix CVE-2025-8033?
To fix CVE-2025-8033, update affected versions of Mozilla Firefox and Firefox ESR to the latest patched versions.
Which versions of Firefox are affected by CVE-2025-8033?
CVE-2025-8033 affects Firefox versions up to 141 and Firefox ESR versions up to 115.26.
What type of vulnerability is CVE-2025-8033?
CVE-2025-8033 is a JavaScript engine vulnerability related to improper handling of closed generators.
Can CVE-2025-8033 be exploited remotely?
CVE-2025-8033 has the potential for remote exploitation as it can lead to application crashes.