CVE-2025-1011: Mozilla Firefox
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A bug in WebAssembly code generation could have lead to a crash. It may have been possible for an attacker to leverage this to achieve code execution. This vulnerability was fixed in Firefox 135, Firefox ESR 128.7, Thunderbird 128.7, and Thunderbird 135.
Affected products
- Mozilla Firefox: before 128.7.0 (fixed in 128.7.0); before 135.0 (fixed in 135.0)
- Mozilla Thunderbird: before 135.0 (fixed in 135.0); from 128.0.1, before 128.7.0 (fixed in 128.7.0)
Published 2025-02-04. Last modified 2026-10-05.