Mozilla Firefox and Thunderbird Cross-Process Memory Leak Vulnerability via IPC Messages

Vulnerability

A vulnerability exists in Mozilla Firefox versions prior to 144, Firefox ESR versions prior to 115.29 and 140.4, as well as Thunderbird versions prior to 144 and 140.4. This vulnerability allows a compromised web process to use malicious inter-process communication (IPC) messages to manipulate the privileged browser process into disclosing blocks of its memory.

Impact

Exploitation of this vulnerability could lead to unauthorized access to memory blocks in the privileged browser process, potentially allowing for further exploitation or information leakage.

Remediation

Users can upgrade to Firefox 144, Firefox ESR 115.29 or 140.4, or Thunderbird 144 or 140.4 to address this vulnerability.

Added: Oct 14, 2025, 1:33 PM
Updated: Oct 14, 2025, 11:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
4.7
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.