Memory Safety Vulnerabilities in Firefox and Thunderbird by Mozilla
CVE-2025-8040

8.8HIGH

Key Information:

Vendor

Mozilla

Vendor
CVE Published:
22 July 2025

What is CVE-2025-8040?

Mozilla has identified memory safety bugs across several versions of Firefox and Thunderbird. These vulnerabilities can lead to potential memory corruption, creating a vector for attackers to exploit. Particularly, the affected versions include Firefox ESR 140.0, Thunderbird ESR 140.0, and their standard counterparts within the 140 series. Users are urged to update to the latest versions to mitigate the risk of arbitrary code execution that could arise from this issue. For detailed remediation steps and further insights, refer to Mozilla's security advisories.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Firefox < 141

Firefox ESR < 140.1

Thunderbird < 141

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrew McCreight, Ashley Zebrowski
.