CVE-2025-9184: Memory safety bugs fixed in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9184?
CVE-2025-9184 has a high severity rating due to potential memory corruption that can lead to arbitrary code execution.
How do I fix CVE-2025-9184?
To fix CVE-2025-9184, update your Firefox or Thunderbird to the latest version available, specifically versions 142 or higher.
Which versions are affected by CVE-2025-9184?
CVE-2025-9184 affects Mozilla Firefox versions up to 142 and Mozilla Thunderbird versions up to 142, including their ESR versions 140.1 and below.
What type of vulnerabilities does CVE-2025-9184 involve?
CVE-2025-9184 involves memory safety bugs that may result in memory corruption.
Can CVE-2025-9184 be exploited?
Yes, if successfully exploited, CVE-2025-9184 could allow an attacker to run arbitrary code on the affected systems.