CVE-2025-1942: Mozilla Firefox
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird 136.
Affected products
Published 2025-03-04. Last modified 2026-10-05.