Monday, May 19, 2025
HomeCVE/vulnerabilityFirefox 138 Launches with Patches for Several High-Severity Flaws

Firefox 138 Launches with Patches for Several High-Severity Flaws

Published on

SIEM as a Service

Follow Us on Google News

Mozilla has officially released Firefox 138, marking a significant update focused on user security. The new version addresses multiple high-severity vulnerabilities, following the Mozilla Foundation Security Advisory 2025-28.

The Firefox browser continues its tradition of proactive security practices, ensuring users are protected from the latest threats.

A Critical Security Update

Announced on April 29, 2025, Firefox 138 includes critical patches for vulnerabilities that, if exploited, could lead to privilege escalation, memory corruption, or even arbitrary code execution.

- Advertisement - Google News

Mozilla has credited security researchers from around the world for responsibly reporting these flaws.

The security advisory highlights four notable CVEs (Common Vulnerabilities and Exposures) fixed in this release.

Below is a summary table of the vulnerabilities, their descriptions, and affected products:

CVETitleImpactAffected Product(s)
CVE-2025-2817Privilege escalation in Firefox UpdaterHighFirefox
CVE-2025-4082WebGL shader attribute memory corruption (macOS only)HighFirefox for macOS
CVE-2025-4083Process isolation bypass via “javascript:” URI links in framesHighFirefox
CVE-2025-4092Memory safety bugs (also affects Thunderbird 138)HighFirefox, Thunderbird

These vulnerabilities, though discovered by security experts and Mozilla’s own fuzzing team, are deemed high risk due to their potential impact.

Privilege escalation, process isolation bypass, and memory corruption can have far-reaching consequences, from compromising user data to facilitating malicious code execution.

Mozilla strongly urges all users to update their browsers to Firefox 138 as soon as possible. Mac users, in particular, should install the update promptly due to the WebGL-specific issue.

Thunderbird users should also check for updates, as one of the memory safety bugs (CVE-2025-4092) affects both products.

With this release, Mozilla once again reinforces its commitment to security and transparency.

Users should remain vigilant by keeping their browsers updated and watching for future advisories. Firefox 138 is now available for download across all supported platforms.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Auth0-PHP Vulnerability Enables Unauthorized Access for Attackers

Critical security vulnerability has been discovered in the Auth0-PHP SDK that could potentially allow...

Active Exploitation of Ivanti EPMM Zero-Day Vulnerability in the Wild

Security researchers at The Shadowserver Foundation have identified active exploitation attempts targeting a critical...

Hacker Arrested for Taking Over SEC Social Media to Spread False Bitcoin News

Alabama man has been sentenced to 14 months in prison for orchestrating a sophisticated...

Investigating Cobalt Strike Beacons Using Shodan: A Researcher’s Guide

Security researcher has revealed a robust method for gathering threat intelligence on Cobalt Strike...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Auth0-PHP Vulnerability Enables Unauthorized Access for Attackers

Critical security vulnerability has been discovered in the Auth0-PHP SDK that could potentially allow...

Active Exploitation of Ivanti EPMM Zero-Day Vulnerability in the Wild

Security researchers at The Shadowserver Foundation have identified active exploitation attempts targeting a critical...

Hacker Arrested for Taking Over SEC Social Media to Spread False Bitcoin News

Alabama man has been sentenced to 14 months in prison for orchestrating a sophisticated...