ADVERTISEMENT

Multiple vulnerabilities in Mozilla products could put governments and businesses at risk

Mozilla has patched multiple vulnerabilities that could have enabled attackers to hijack user devices.

Mozilla vulnerabilities

Image by Cybernews

Paulina Okunytė
Paulina Okunytė Senior Journalist
March 12, 2025 Updated: March 12, 2025 1 min read
  • Thunderbird versions prior to ESR 128.8
  • Thunderbird versions prior to 136
  • Firefox ESR versions prior to 128.8
  • Firefox ESR versions prior to 115.2.1
  • Firefox versions prior to 136
ADVERTISEMENT
  • CVE-2024-43097 could cause a memory overflow in graphics rendering, leading to crashes or exploits.
  • CVE-2025-1930 and CVE-2025-1931 involve use-after-free (UAF) bugs in AudioIPC and WebTransportChild, which could let attackers escape browser sandboxes or execute remote code.
  • CVE-2025-1932 could allow unauthorized memory access via an XSLT sorting flaw, potentially causing crashes or data leaks.
  • CVE-2025-1933 could corrupt WASM i32 return values on 64-bit CPUs, leading to incorrect execution or security risks.
  • CVE-2025-1937, CVE-2025-1938, and CVE-2025-1943 involve memory safety bugs in Firefox and Thunderbird that could enable remote code execution.
  • CVE-2025-1939 exploits Android Custom Tabs animations for tapjacking, tricking users into granting unintended permissions.
Ernestas Naprys vilius Gintaras Radauskas Paulina Okunyte
Don’t miss our latest stories on Google News
Add us as your Preferred Source on Google.
  • CVE-2025-26696 could make a fake encrypted email look real, exposing sensitive info.
  • CVE-2025-26695 could let attackers swap OpenPGP keys, enabling impersonation.
  • CVE-2025-1934 could crash the browser or run harmful code.
  • CVE-2025-1935 could trick users into registering malicious protocol handlers.
  • CVE-2025-1936 could hide malware inside JAR files by faking file extensions.
  • CVE-2025-1942 could leak memory data when converting text.
  • CVE-2025-1940 could tapjack Android prompts, tricking users into confirming unwanted actions.
  • CVE-2024-9956 could allow passkey phishing over Bluetooth.
  • CVE-2025-1941 could bypass Firefox Focus’s lock screen for Android, exposing browser data.
ADVERTISEMENT