Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
History

Tue, 29 Apr 2025 13:30:00 +0000

Type Values Removed Values Added
Description Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vulnerabilities, could be used to escalate privileges. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 138, Firefox ESR < 128.10, Firefox ESR < 115.23, Thunderbird < 138, and Thunderbird ESR < 128.10.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published: 2025-04-29T13:13:35.242Z

Updated: 2025-04-30T03:56:27.933Z

Reserved: 2025-04-29T13:13:34.532Z

Link: CVE-2025-4082

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-04-29T14:15:34.913

Modified: 2025-04-29T14:15:34.913

Link: CVE-2025-4082

cve-icon Redhat

No data.