The security advisory, MFSA 2025-28, details a range of flaws-several of which could enable attackers to escalate privileges, execute arbitrary code, or compromise sensitive user data.
The most severe vulnerabilities fixed in Firefox 138 include:
javascript: URIsjavascript: URIs in cross-origin frames allowed content to execute in the top-level document’s process rather than its intended frame. | CVE ID | Impact | Component/Feature | Affected Platform(s) | Exploit Type |
|---|---|---|---|---|
| CVE-2025-2817 | High | Updater | All | Privilege Escalation |
| CVE-2025-4082 | High | WebGL Shader | macOS | Memory Corruption |
| CVE-2025-4083 | High | javascript: URI Handling | All | Process Isolation Bypass |
| CVE-2025-4085 | Moderate | UITour Actor | All | Info Leak/Privilege Escalation |
| CVE-2025-4086 | Moderate | Download Dialog | Android | Obscured Download Type |
| CVE-2025-4087 | Moderate | XPath Parsing | All | Memory Corruption |
| CVE-2025-4088 | Moderate | Storage Access API | All | CSRF |
| CVE-2025-4089 | Moderate | “Copy as cURL” Command | All | Local Code Execution |
| CVE-2025-4090 | Low | Logcat Logging | Android | Info Leak |
| CVE-2025-4091/92 | Moderate/High | General Memory Safety | All | Arbitrary Code Execution |
Mozilla urges all users to update to Firefox 138 immediately to mitigate these vulnerabilities.
Organizations should prioritize patching, especially where browsers are used with elevated privileges or in sensitive environments.
No evidence currently suggests these flaws are being actively exploited in the wild.
For technical details and the full list of fixes, consult the official Mozilla Security Advisory MFSA 2025-28.
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates
The post Firefox 138 Patches Multiple High-Severity Security Flaws appeared first on Cyber Security News.
The global energy industry has long depended on seismic data to locate oil and gas…
Artificial intelligence is quietly transforming every corner of modern industry. From predictive maintenance in heavy…
Additive manufacturing has always lived in a bit of a gray area. Some see it…
The global energy industry has long depended on seismic data to locate oil and gas…
Artificial intelligence is quietly transforming every corner of modern industry. From predictive maintenance in heavy…
Additive manufacturing has always lived in a bit of a gray area. Some see it…
This website uses cookies.