CVE-2025-49710: Mozilla Firefox
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
An integer overflow was present in `OrderedHashTable` used by the JavaScript engine. This vulnerability was fixed in Firefox 139.0.4.
Affected products
- Mozilla Firefox: before 139.0.4 (fixed in 139.0.4)
Published 2025-06-11. Last modified 2026-10-05.