CVE-2025-9179
Mozilla · Firefox, Thunderbird
A memory corruption vulnerability in the GMP (Gecko Media Plugin) process allows for potential remote code execution when processing encrypted media.
Executive summary
A critical memory corruption vulnerability in Mozilla Firefox and Thunderbird could allow an unauthenticated attacker to execute arbitrary code via malicious encrypted media.
Vulnerability
This is a memory corruption flaw within the Gecko Media Plugin (GMP) process, which handles encrypted media playback. The vulnerability is exploitable by an unauthenticated, remote attacker via crafted content.
Business impact
Successful exploitation of this vulnerability can lead to full system compromise, as it allows for arbitrary code execution. Given the CVSS score of 9.8, this represents the highest level of severity, potentially leading to data exfiltration, unauthorized access to user sessions, and complete loss of system confidentiality, integrity, and availability.
Remediation
Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to the versions specified in the vendor advisories (e.g., 142 or later).
Proactive Monitoring: Monitor browser and email client process logs for unexpected crashes, which may indicate attempted exploitation of the GMP sandbox.
Compensating Controls: Ensure that endpoint protection software is active and that the browser's built-in sandbox remains enabled, as this provides a secondary layer of defense against memory-based attacks.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Due to the critical nature of this memory corruption flaw, organizations should prioritize patching across all workstations immediately. Given the ubiquity of these browsers, failure to update significantly increases the risk of remote code execution attacks.