CVE 9.8 CRITICAL

CVE-2025-11719_CVE-2025-11719

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.

Basic Information

ID CVE-2025-11719
Source mozilla
Published Oct 14, 2025 at 12:27
Modified Oct 15, 2025 at 13:24

Affected Product

Vendor Mozilla
Product Firefox
Version unspecified
Affected Versions Mozilla Firefox unspecified
Mozilla Thunderbird unspecified

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.