CVE-2025-9179: Sandbox escape due to invalid pointer in the Audio/Video: GMP component
An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9179?
CVE-2025-9179 has been rated as a critical vulnerability due to its potential for memory corruption in the GMP process.
How do I fix CVE-2025-9179?
To fix CVE-2025-9179, update Firefox to version 142 or later, and Firefox ESR to 115.27, 128.14, or higher.
Which versions are affected by CVE-2025-9179?
CVE-2025-9179 affects Firefox versions prior to 142 and Firefox ESR versions prior to 115.27 and 128.14.
What products are impacted by CVE-2025-9179?
The impacted products include Mozilla Firefox, Firefox ESR, and Mozilla Thunderbird versions below the specified thresholds.
Is CVE-2025-9179 a local or remote vulnerability?
CVE-2025-9179 is categorized as a remote vulnerability, potentially exploited over the network.