CVE-2025-9185: Memory safety bugs fixed in Firefox ESR 115.27, Firefox ESR 128.14, Thunderbird ESR 128.14, Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142
Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9185?
CVE-2025-9185 is classified as a high severity vulnerability due to its potential for memory corruption exploitation.
How do I fix CVE-2025-9185?
To fix CVE-2025-9185, users should update to the latest version of Mozilla Firefox or Thunderbird where the vulnerability has been patched.
Which versions of Firefox are affected by CVE-2025-9185?
CVE-2025-9185 affects Firefox versions up to 142 and Firefox ESR versions up to 115.27, 128.14, and 140.2.
Which versions of Thunderbird are susceptible to CVE-2025-9185?
CVE-2025-9185 affects Thunderbird versions up to 142 and Thunderbird ESR versions up to 128.14 and 140.2.
What are the potential impacts of CVE-2025-9185?
The potential impacts of CVE-2025-9185 include unauthorized access to sensitive data and possible system compromise due to memory safety issues.