Description
A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.12.
Product status
128.12 (rpm)
140 (rpm)
140 (rpm)
Credits
LJP and HexRabbit (DEVCORE Research Team)
References
lists.debian.org/debian-lts-announce/2025/07/msg00002.html
lists.debian.org/debian-lts-announce/2025/06/msg00029.html
bugzilla.mozilla.org/show_bug.cgi?id=1966423
www.mozilla.org/security/advisories/mfsa2025-51/
www.mozilla.org/security/advisories/mfsa2025-52/
www.mozilla.org/security/advisories/mfsa2025-53/
www.mozilla.org/security/advisories/mfsa2025-54/
www.mozilla.org/security/advisories/mfsa2025-55/