CVE-2025-11719: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability was fixed in Firefox 144 and Thunderbird 144.

Affected products

  • Mozilla Firefox: from 143.0, before 144.0 (fixed in 144.0)
  • Mozilla Thunderbird: from 143.0, before 144.0 (fixed in 144.0)

Published 2025-10-14. Last modified 2026-06-17.