CVE-2025-10528

7.3

Mozilla · Firefox, Thunderbird

A sandbox escape vulnerability in the Graphics: Canvas2D component of Mozilla Firefox and Thunderbird allows for potential system compromise due to undefined behavior and invalid pointers.

Executive summary

Mozilla has addressed a high-severity sandbox escape vulnerability in Firefox and Thunderbird that could allow attackers to bypass security boundaries.

Vulnerability

This is a sandbox escape flaw stemming from undefined behavior and an invalid pointer within the Graphics: Canvas2D component. The vulnerability is exploitable by an unauthenticated remote attacker without requiring user interaction.

Business impact

The ability to escape the browser sandbox represents a significant security failure that could lead to unauthorized system access or arbitrary code execution. Given the CVSS score of 7.3, this vulnerability poses a high risk to organizational endpoints by potentially compromising the underlying operating system. If successfully exploited, this could result in data theft, malware installation, or persistent unauthorized access to corporate devices.

Remediation

Immediate Action: Update all instances of Mozilla Firefox and Mozilla Thunderbird to version 143 or the corresponding ESR version 140.3 immediately.

Proactive Monitoring: Review endpoint security logs for signs of unusual process behavior or unexpected crashes related to browser rendering components.

Compensating Controls: While no direct virtual patch exists for this specific sandbox escape, ensure that browser isolation policies are enforced and that the principle of least privilege is applied to all user accounts to minimize the potential impact of a successful escape.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a high risk to the integrity of user workstations and corporate environments. Security teams should prioritize the deployment of the provided patches across the enterprise to ensure all installations of Firefox and Thunderbird are updated to the secure versions. Failure to patch may expose the organization to exploitation, and immediate action is required to close this security gap.

More Mozilla CVEs

Sources

Originally found and disclosed by Oskar L, per the CVE Program record.