Out-of-Bounds Read/Write Vulnerability in Firefox Browser
CVE-2025-4920

Currently unrated

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
17 May 2025

What is CVE-2025-4920?

CVE-2025-4920 is an out-of-bounds read/write vulnerability identified in the Firefox browser, developed by Mozilla. This vulnerability occurs when the software improperly handles certain conditions, potentially allowing attackers to access sensitive information or manipulate memory in ways not intended by the developers. As Firefox is a widely used web browser, any exploit leveraging this vulnerability could significantly compromise user security and privacy, affecting individuals and organizations alike. If successfully executed, attackers could leverage this flaw to execute arbitrary code or cause crashes, disrupting normal browsing operations and potentially exposing users to further security risks.

Potential Impact of CVE-2025-4920

  1. Data Leakage: A successful exploit could allow unauthorized access to sensitive data stored in memory, leading to potential data breaches that could affect user accounts and organizational data.

  2. System Instability: Exploitation of the vulnerability could result in application crashes, leading to a loss of productivity and negatively impacting user experience across all devices running the affected version of Firefox.

  3. Increased Attack Surface: If the vulnerability is exploited, it could facilitate further attacks, such as malware installation or additional intrusion attempts, significantly increasing the threat landscape for users and organizations reliant on Mozilla Firefox for web access.

Affected Version(s)

Firefox < 138.0.4

Firefox ESR < 128.10.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Edouard Bochin and Tao Yan from Palo Alto Networks working with Trend Micro's Zero Day Initiative
.