Mozilla Firefox and Thunderbird Use-After-Free Vulnerability in Custom Highlight API

Vulnerability

A use-after-free vulnerability has been identified in Mozilla Firefox versions prior to 135, Firefox ESR versions prior to 115.20 and 128.7, as well as in Thunderbird versions prior to 128.7 and 135. This vulnerability could have been exploited to cause a crash, potentially leading to arbitrary code execution.

Impact

Exploitation of this vulnerability could have caused a crash, with the potential for arbitrary code execution.

Remediation

Users can upgrade to Firefox 135, Firefox ESR 115.20 or 128.7, or Thunderbird 128.7 or 135 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.