Home Any version before 137
affected
Any version before 137
affected
Description
An attacker could read 32 bits of values spilled onto the stack in a JIT compiled function. This vulnerability affects Firefox < 137 and Thunderbird < 137.
Problem types
JIT optimization bug with different stack slot sizes
Product status
Credits
anbu
References
bugzilla.mozilla.org/show_bug.cgi?id=1947141
www.mozilla.org/security/advisories/mfsa2025-20/
www.mozilla.org/security/advisories/mfsa2025-23/
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.