Out-of-Bounds Read and Write Vulnerability in Firefox ESR by Mozilla
CVE-2025-4918

7.5HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
17 May 2025

Badges

πŸ”₯ Trending nowπŸ₯‡ Trended No. 1πŸ“ˆ TrendedπŸ“ˆ Score: 5,650πŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2025-4918?

CVE-2025-4918 is a vulnerability identified in the Mozilla Firefox Extended Support Release (ESR) browser, specifically affecting versions prior to 138.0.4, 128.10.1, and 115.23.1. The issue arises due to an out-of-bounds read and write error associated with JavaScript Promise objects. This technical defect can allow attackers to manipulate memory, which might lead to the leakage of sensitive data or the corruption of data within the application. Given that Firefox is widely employed for both personal and organizational web browsing, this vulnerability poses considerable risks to businesses that rely on it for secure operations and communications.

Potential impact of CVE-2025-4918

  1. Data Leakage: Due to the nature of the out-of-bounds read vulnerability, attackers could exploit this flaw to gain unauthorized access to sensitive information stored in memory. This could lead to data breaches where confidential data is exposed, resulting in reputational damage and regulatory implications for organizations.

  2. System Stability Compromise: Exploiting out-of-bounds write vulnerabilities can cause critical application failures. The potential for crashes or unforeseen behavior in Firefox due to memory corruption could disrupt workflows and degrade the user experience, leading to lost productivity.

  3. Increased Attack Surface: The existence of this vulnerability increases the attack surface for threat actors, making it easier for them to launch targeted exploits, especially in environments where Firefox is integrated into larger security frameworks or used for accessing enterprise applications. This could pave the way for further attacks on internal systems or networks.

Affected Version(s)

Firefox < 138.0.4

Firefox ESR < 128.10.1

Firefox ESR < 115.23.1

News Articles

Firefox 0-day Vulnerabilities Let Attackers Execute Malicious Code

Mozilla has released an emergency security update to address two critical vulnerabilities in Firefox that could allow attackers.

6 days ago

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ₯‡

    Vulnerability reached the number 1 worldwide trending spot

  • πŸ“ˆ

    Vulnerability started trending

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by CybersecurityNews

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edouard Bochin and Tao Yan from Palo Alto Networks working with Trend Micro's Zero Day Initiative
.
CVE-2025-4918 : Out-of-Bounds Read and Write Vulnerability in Firefox ESR by Mozilla