We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
Reserved 2025-05-17 | Published 2025-05-17 | Updated 2025-05-22 | Assigner mozillaOut-of-bounds access when resolving Promise objects
Edouard Bochin and Tao Yan from Palo Alto Networks working with Trend Micro's Zero Day Initiative
bugzilla.mozilla.org/show_bug.cgi?id=1966612
www.mozilla.org/security/advisories/mfsa2025-36/
www.mozilla.org/security/advisories/mfsa2025-37/
www.mozilla.org/security/advisories/mfsa2025-38/
www.mozilla.org/security/advisories/mfsa2025-40/
www.mozilla.org/security/advisories/mfsa2025-41/
Support options