CVE-2025-49709: Mozilla Firefox

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Certain canvas operations could have lead to memory corruption. This vulnerability was fixed in Firefox 139.0.4.

Affected products

  • Mozilla Firefox: before 139.0.4 (fixed in 139.0.4)

Published 2025-06-11. Last modified 2026-09-30.