PT-2025-21808 · Mozilla+11 · Firefox Esr+11

Edouard Bochin

+1

·

Published

2025-05-17

·

Updated

2025-10-01

·

CVE-2025-4918

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox versions prior to 138.0.4 Firefox ESR versions prior to 128.10.1 Firefox ESR versions prior to 115.23.1
Description An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object. This issue was demonstrated during Pwn2Own Berlin 2025, where it was used to trigger out-of-bounds memory access. The vulnerability allows for code execution.
Recommendations For Firefox versions prior to 138.0.4, update to version 138.0.4 or later. For Firefox ESR versions prior to 128.10.1, update to version 128.10.1 or later. For Firefox ESR versions prior to 115.23.1, update to version 115.23.1 or later.

Exploit

Fix

RCE

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:8049
ALSA-2025:8060
ALSA-2025:8125
ALSA-2025:8607
ALSA-2025:8608
ALSA-2025:8756
ALT-PU-2025-11495
ALT-PU-2025-11497
ALT-PU-2025-7169
ALT-PU-2025-8348
ALT-PU-2025-8611
ALT-PU-2025-8725
BDU:2025-06016
CESA-2025_8060
CESA-2025_8756
CVE-2025-4918
DLA-4172-1
DLA-4194-1
DSA-5922-1
DSA-5932-1
INFSA-2025_8049
INFSA-2025_8060
INFSA-2025_8607
INFSA-2025_8756
MGASA-2025-0165
MGASA-2025-0168
OESA-2025-1545
OESA-2025-1546
OESA-2025-1547
OESA-2025-1548
OESA-2025-1835
OPENSUSE-SU-2025:15133-1
OPENSUSE-SU-2025:15148-1
OPENSUSE-SU-2025:15149-1
OPENSUSE-SU-2025_01701-1
RHSA-2025:8049
RHSA-2025:8060
RHSA-2025:8125
RHSA-2025:8369
RHSA-2025:8370
RHSA-2025:8371
RHSA-2025:8465
RHSA-2025:8598
RHSA-2025:8599
RHSA-2025:8607
RHSA-2025:8608
RHSA-2025:8628
RHSA-2025:8629
RHSA-2025:8630
RHSA-2025:8631
RHSA-2025:8639
RHSA-2025:8640
RHSA-2025:8642
RHSA-2025:8645
RHSA-2025:8756
RHSA-2025:8807
RHSA-2025_8049
RHSA-2025_8060
RHSA-2025_8607
RHSA-2025_8756
SUSE-SU-2025:01701-1
SUSE-SU-2025:01710-1
SUSE-SU-2025:01813-1
SUSE-SU-2025_01701-1
SUSE-SU-2025_01710-1
USN-7663-1
ZDI-25-292

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Firefox Esr
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu