CVE-2019-17008: Use After Free
Last updated 25 August 2025
Other sources
When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2019-17008?
CVE-2019-17008 is a vulnerability that occurs when using nested workers, resulting in a potentially exploitable crash.
Which software are affected by CVE-2019-17008?
Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71 are affected by CVE-2019-17008.
What is the severity of CVE-2019-17008?
CVE-2019-17008 has a severity score of 8.8 (high).
How can I fix CVE-2019-17008?
To fix CVE-2019-17008, update Thunderbird to version 68.3 or later, Firefox ESR to version 68.3 or later, and Firefox to version 71 or later.
Where can I find more information about CVE-2019-17008?
You can find more information about CVE-2019-17008 at the following references: [reference 1], [reference 2], [reference 3].