CVE-2025-11709: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipulated WebGL textures. This vulnerability was fixed in Firefox 144, Firefox ESR 115.29, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Affected products

  • Mozilla Firefox: before 115.29.0 (fixed in 115.29.0); before 144.0 (fixed in 144.0); from 116.0, before 140.4.0 (fixed in 140.4.0)
  • Mozilla Thunderbird: before 144.0 (fixed in 144.0)

Published 2025-10-14. Last modified 2026-06-17.