Description
Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could lead to crashes caused by use-after-free memory corruption. This vulnerability affects Firefox < 144 and Thunderbird < 144.
Problem types
Use-after-free caused by the native messaging web extension API on Windows
Product status
Credits
Filip Štamcar
References
bugzilla.mozilla.org/show_bug.cgi?id=1991950
www.mozilla.org/security/advisories/mfsa2025-81/
www.mozilla.org/security/advisories/mfsa2025-84/