Mozilla Firefox and Thunderbird Use-After-Free Vulnerability in MediaTrackGraphImpl::GetInstance()

Vulnerability

A use-after-free vulnerability has been identified in the MediaTrackGraphImpl::GetInstance() function, affecting multiple versions of Firefox and Thunderbird. This vulnerability could potentially be exploited to cause memory corruption, leading to crashes or arbitrary code execution.

Impact

Exploitation of this vulnerability could result in memory corruption, causing crashes or potentially allowing for arbitrary code execution.

Remediation

Users can upgrade to Firefox 144, Firefox ESR 140.4, Thunderbird 144, or Thunderbird ESR 140.4 to address this vulnerability.

Added: Oct 14, 2025, 1:35 PM
Updated: Oct 14, 2025, 11:48 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.