MFSA-RESERVE-2025-1937097: High severity thunderbird vulnerability
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.
Other sources
Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges.This bug only affects Thunderbird for macOS. Other versions of Thunderbird are unaffected.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of MFSA-RESERVE-2025-1937097?
The severity of MFSA-RESERVE-2025-1937097 is high due to the potential for privilege escalation through an out-of-bounds read.
How do I fix MFSA-RESERVE-2025-1937097?
To fix MFSA-RESERVE-2025-1937097, update Firefox to version 138 or later, or update Firefox ESR to version 115.23 or 128.10.
Which versions of Firefox are affected by MFSA-RESERVE-2025-1937097?
Only Firefox for macOS versions prior to 138 are affected by MFSA-RESERVE-2025-1937097.
Is Thunderbird affected by MFSA-RESERVE-2025-1937097?
Yes, Thunderbird versions prior to 138 are also affected by MFSA-RESERVE-2025-1937097.
Can other operating systems be impacted by MFSA-RESERVE-2025-1937097?
No, MFSA-RESERVE-2025-1937097 only affects Firefox for macOS; other operating systems are unaffected.