An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
History

Wed, 20 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 19 Aug 2025 20:45:00 +0000

Type Values Removed Values Added
Description An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-08-19T20:33:53.949Z

Updated: 2025-08-20T15:18:57.429Z

Reserved: 2025-08-19T15:55:37.418Z

Link: CVE-2025-9179

cve-icon Vulnrichment

Updated: 2025-08-20T14:06:17.281Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-08-19T21:15:30.247

Modified: 2025-08-20T16:15:46.523

Link: CVE-2025-9179

cve-icon Redhat

No data.