CVE-2025-1931: Use-after-free in WebTransportChild
It was possible to cause a use-after-free in the content process side of a WebTransport connection, leading to a potentially exploitable crash.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1931?
CVE-2025-1931 has been categorized as a potentially exploitable vulnerability that can lead to a crash.
How do I fix CVE-2025-1931?
To fix CVE-2025-1931, upgrade to Mozilla Firefox version 136 or Mozilla Firefox ESR versions 115.21 or 128.8.
What causes CVE-2025-1931?
CVE-2025-1931 is caused by a use-after-free error in the content process of a WebTransport connection.
Which software versions are affected by CVE-2025-1931?
Affected software includes Mozilla Firefox versions up to 136 and Mozilla Firefox ESR versions up to 115.21 and 128.8.
Can CVE-2025-1931 be exploited remotely?
Yes, CVE-2025-1931 may potentially be exploited remotely, leading to a crash of the affected application.