CVE-2025-4918 Details
Description
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
A critical out-of-bounds read or write vulnerability has been identified in JavaScript `Promise` objects, affecting multiple versions of Firefox and Thunderbird. This vulnerability allows attackers to manipulate memory, potentially leading to arbitrary code execution. In general, these flaws cannot be exploited through email in the Thunderbird product because scripting is disabled when reading mail, but are potentially risks in browser or browser-like contexts.
Users can upgrade to Firefox 138.0.4, Firefox ESR 128.10.1 or 115.23.1, or Thunderbird 128.10.2 or 138.0.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/05/msg00024.html | CVE | |
| https://lists.debian.org/debian-lts-announce/2025/05/msg00046.html | CVE | |
| https://www.vicarius.io/vsociety/posts/cve-2025-4918-detect-firefox-out-of-bounds-write | CVE | ExploitThird Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-4918-mitigate-firefox-out-of-bounds-write | CVE | ExploitThird Party Advisory |
| https://bugzilla.mozilla.org/show_bug.cgi?id=1966612 | [email protected] | Permissions Required |
| https://www.mozilla.org/security/advisories/mfsa2025-36/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-37/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-38/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-40/ | [email protected] | Vendor Advisory |
| https://www.mozilla.org/security/advisories/mfsa2025-41/ | [email protected] | Vendor Advisory |
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| mozilla firefox | < 115.23.1 < 138.0.4 >= 116.0, < 128.10.1 |
CPE
Remediation
| |
| mozilla thunderbird | < 128.10.2 >= 138.0, < 138.0.2 |
CPE
Remediation
| |
Change History
11 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | CVE Modified | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Sep 22, 2025 | CVE Modified | CISA-ADP |
| May 28, 2025 | Initial Analysis | [email protected] |
| May 22, 2025 | CVE Modified | [email protected] |
| May 21, 2025 | CVE Modified | CVE |
| May 19, 2025 | CVE Modified | CISA-ADP |
| May 18, 2025 | CVE Modified | [email protected] |
| May 17, 2025 | New CVE Received | [email protected] |