CVE-2025-0240: Compartment mismatch when parsing JavaScript JSON module
Last updated 9 January 2025
Other sources
Parsing a JavaScript module as JSON could under some circumstances cause cross-compartment access, which may result in a use-after-free.
— Mozilla
Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0240?
CVE-2025-0240 is considered a critical vulnerability due to its potential for causing a use-after-free condition.
How do I fix CVE-2025-0240?
To fix CVE-2025-0240, update affected software to the versions specified in the vulnerability report.
What software is affected by CVE-2025-0240?
CVE-2025-0240 affects Mozilla Firefox, Firefox ESR, and Thunderbird versions up to 134 and 128.6 respectively.
What vulnerabilities can occur due to CVE-2025-0240?
CVE-2025-0240 may lead to cross-compartment access, resulting in potential code execution or memory corruption.
When was CVE-2025-0240 last updated?
CVE-2025-0240 was last updated on 9 January 2025.