CVE-2025-8028

9.8

Mozilla · Firefox, Thunderbird

A memory corruption vulnerability exists in the WASM `br_table` instruction on arm64 architectures, potentially leading to incorrect branch addresses and system instability.

Executive summary

A critical memory corruption vulnerability in the WASM engine of Mozilla Firefox and Thunderbird on arm64 devices could allow for arbitrary code execution.

Vulnerability

This is a memory corruption flaw triggered by a WASM br_table instruction that results in address truncation. It is an unauthenticated, network-accessible vulnerability that can be exploited via malicious web content.

Business impact

With a CVSS score of 9.8, this vulnerability is extremely critical as it allows for potential remote code execution (RCE) on the host system. The impact extends to total loss of confidentiality, integrity, and availability, making it a prime target for exploitation to gain a foothold on user workstations.

Remediation

Immediate Action: Apply the latest security updates for Mozilla Firefox and Thunderbird, specifically versions 115.26, 128.13, 140.1, or later, depending on the release channel.

Proactive Monitoring: Utilize endpoint security tools to monitor for crashes or unexpected process termination in web browsers.

Compensating Controls: Restrict access to untrusted websites and utilize browser-based security extensions that block arbitrary or malicious script execution.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the 9.8 CVSS score and the potential for RCE, this update is of the highest priority. Organizations should deploy the patched versions of Firefox and Thunderbird across all arm64-based endpoints immediately to mitigate the risk of remote compromise.

More Mozilla CVEs