CVE-2025-3608: Mozilla Firefox
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition. This vulnerability was fixed in Firefox 137.0.2.
Affected products
- Mozilla Firefox: before 137.0.2 (fixed in 137.0.2)
Published 2025-04-15. Last modified 2026-09-30.