CVE-2025-5262: Mozilla Thunderbird
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 139 and Thunderbird < 128.11.
Affected products
- Mozilla Thunderbird: before 128.11.0 (fixed in 128.11.0); before 139.0 (fixed in 139.0)
Published 2025-05-27. Last modified 2026-06-17.