Remote Code Execution Vulnerability in Firefox by Mozilla
CVE-2025-10529
6.5MEDIUM
Key Information:
- Vendor
Mozilla
- Vendor
- CVE Published:
- 16 September 2025
What is CVE-2025-10529?
A remote code execution vulnerability has been identified in Firefox versions below 143 and Firefox Extended Support Release (ESR) below 140.3. This vulnerability allows attackers to execute arbitrary code on affected installations, which could lead to unauthorized access and manipulation of user systems. It is crucial for Firefox users to update to the latest version to mitigate potential exploitation risks.
Affected Version(s)
Firefox < 143
Firefox ESR < 140.3
Thunderbird < 143
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Daniel Holbert