CVE-2025-1933: JIT corruption of WASM i32 return values on 64-bit CPUs
Last updated 6 March 2025
Other sources
On 64-bit CPUs, when the JIT compiles WASM i32 return values they can pick up bits from left over memory. This can potentially cause them to be treated as a different type.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1933?
CVE-2025-1933 has been rated as important due to the potential for uninitialized memory usage leading to various vulnerabilities.
How do I fix CVE-2025-1933?
To remediate CVE-2025-1933, update your Mozilla Firefox to version 136 or later, or Firefox ESR to the appropriate patched versions.
What software is affected by CVE-2025-1933?
CVE-2025-1933 affects Mozilla Firefox versions up to 136, Firefox ESR versions up to 115.21 and 128.8, as well as Thunderbird versions up to 136 and 128.8.
What exploit scenarios exist for CVE-2025-1933?
CVE-2025-1933 could potentially allow attackers to manipulate i32 return values in WebAssembly, which may lead to unexpected behaviors or application crashes.
When was CVE-2025-1933 disclosed?
CVE-2025-1933 was disclosed as part of Mozilla's ongoing security advisories related to its web browser and related software products.