CVE-2025-9182

7.5

Mozilla · Firefox, Thunderbird

A denial of service vulnerability exists in the Graphics WebRender component of Mozilla Firefox and Thunderbird, which can be triggered by an out of memory condition.

Executive summary

Mozilla Firefox and Thunderbird are vulnerable to a denial of service attack through an out of memory error in the WebRender component, which may lead to application instability or crashes.

Vulnerability

This is an unauthenticated denial of service vulnerability located within the Graphics WebRender component. It allows an attacker to cause an out of memory state, leading to service disruption without requiring prior authentication.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk to service availability. Successful exploitation results in the abrupt termination of the browser or email client, which causes user productivity loss and potential data corruption if active tasks are interrupted during the crash.

Remediation

Immediate Action: Update Mozilla Firefox and Mozilla Thunderbird to the versions specified in the vendor security advisory (Firefox 142, Firefox ESR 140.2, Thunderbird 142, or Thunderbird 140.2).

Proactive Monitoring: Monitor system logs for frequent application restarts or unexpected process terminations that may indicate exploitation attempts.

Compensating Controls: Ensure that endpoint protection software is active and that users are restricted from accessing untrusted or malicious web content that may attempt to trigger memory intensive rendering tasks.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high impact on service availability and the ease of triggering the vulnerability remotely, organizations should prioritize deploying the provided updates across all enterprise workstations. Patching is the only effective method to resolve this memory management flaw and restore system stability.

More Mozilla CVEs

Sources

Originally found and disclosed by Irvan Kurniawan, per the CVE Program record.