CVE-2025-11709 Details
Description
A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
A vulnerability exists in Mozilla Firefox and Thunderbird that allows a compromised web process to perform out-of-bounds reads and writes in a more privileged process. This exploitation is achieved through manipulated WebGL textures. The issue affects multiple versions of Firefox and Thunderbird, with specific version ranges detailed in the advisory.
Users can upgrade to Firefox 144, Firefox ESR 140.4, Thunderbird 144, or Thunderbird ESR 140.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 115.29.0 < 144.0 >= 116.0, < 140.4.0 |
CPE
Remediation
| |
| mozilla thunderbird | < 144.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 17, 2025 | Initial Analysis | [email protected] |
| Oct 15, 2025 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | New CVE Received | [email protected] |