CVE-2025-1938: Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Memory safety bugs present in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1938?
CVE-2025-1938 has a high severity rating due to the potential for memory corruption that could allow arbitrary code execution.
How do I fix CVE-2025-1938?
To fix CVE-2025-1938, update Mozilla Firefox to version 136 or Thunderbird to the latest version available.
What software is affected by CVE-2025-1938?
CVE-2025-1938 affects Firefox versions up to 135, Thunderbird versions up to 135, and Firefox ESR versions up to 128.7.
Can CVE-2025-1938 be exploited?
There is a possibility that CVE-2025-1938 could be exploited to run arbitrary code if attackers leverage the memory safety bugs.
What should I do if I cannot update to a new version for CVE-2025-1938?
If you cannot update, consider using alternative browsers until a fix is applied or apply additional security measures to reduce risk.