First published: Tue Apr 29 2025(Updated: )
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.
Affected Software | Affected Version | How to fix |
---|---|---|
Thunderbird | <138 | 138 |
Firefox ESR | <115.23 | 115.23 |
Firefox ESR | <128.10 | 128.10 |
Mozilla Thunderbird | <128.10 | 128.10 |
Firefox | <138 | 138 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
The severity of MFSA-RESERVE-2025-1937097 is high due to the potential for privilege escalation through an out-of-bounds read.
To fix MFSA-RESERVE-2025-1937097, update Firefox to version 138 or later, or update Firefox ESR to version 115.23 or 128.10.
Only Firefox for macOS versions prior to 138 are affected by MFSA-RESERVE-2025-1937097.
Yes, Thunderbird versions prior to 138 are also affected by MFSA-RESERVE-2025-1937097.
No, MFSA-RESERVE-2025-1937097 only affects Firefox for macOS; other operating systems are unaffected.