Mozilla Firefox and Thunderbird Out-of-Bounds Read/Write Vulnerability via WebGL Textures

Vulnerability

A vulnerability exists in Mozilla Firefox and Thunderbird that allows a compromised web process to perform out-of-bounds reads and writes in a more privileged process. This exploitation is achieved through manipulated WebGL textures. The issue affects multiple versions of Firefox and Thunderbird, with specific version ranges detailed in the advisory.

Impact

Exploitation of this vulnerability could lead to memory corruption, with evidence suggesting that such corruption could be leveraged to execute arbitrary code.

Remediation

Users can upgrade to Firefox 144, Firefox ESR 140.4, Thunderbird 144, or Thunderbird ESR 140.4 to address this vulnerability.

Added: Oct 14, 2025, 1:34 PM
Updated: Oct 14, 2025, 11:47 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.0
exploitability
4.4
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.