CVE-2025-4082

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 125

Summary

CVE-2025-4082 is a vulnerability affecting Thunderbird for macOS. It allows an attacker to modify specific WebGL shader attributes, triggering an out-of-bounds read. When exploited in conjunction with other vulnerabilities, this issue could be used to escalate privileges. This bug only impacts Thunderbird versions below 138 for macOS, as well as select Firefox and Thunderbird Enterprise releases. Firefox versions 138 and above, Firefox ESR 128.10 and later, and Thunderbird version 138 and above are not affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Firefox
  • Mozilla Thunderbird

Affected Vendors

  • Mozilla