CVE-2025-4091

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 29, 2025
Updated: May 9, 2025
CWE ID 119

Summary

CVE-2025-4091 is a memory safety issue affecting Firefox versions prior to 138 and Firefox ESR versions below 128.10, as well as Thunderbird versions below 138 and Thunderbird ESR versions below 128.10. These bugs, which include memory corruption vulnerabilities, pose a potential risk for arbitrary code execution. Despite no confirmed exploits being reported, it is assumed that some of these bugs could be exploited given enough effort. Users are advised to update their Firefox and Thunderbird installations to the latest versions to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mozilla Firefox
  • Mozilla Thunderbird

Affected Vendors

  • Mozilla