#21588 closed enhancement (fixed)
js-128.10.1 (spidermonkey) and firefox-128.10.1
| Reported by: | zeckma | Owned by: | zeckma |
|---|---|---|---|
| Priority: | high | Milestone: | 12.4 |
| Component: | BOOK | Version: | git |
| Severity: | critical | Keywords: | |
| Cc: |
Description
This security update fixes two CVEs rated critical by Mozilla, Thunderbird is sure to follow.
This updates fixes:
- CVE-2025-4920
- CVE-2025-4921
I will explain the CVEs in detail in a comment.
Change History (8)
comment:1 by , 17 months ago
| Severity: | normal → critical |
|---|
comment:3 by , 17 months ago
| Summary: | firefox and spidermonkey 128.10.1 → js-128.10.1 (spidermonkey) and firefox-128.10.1 |
|---|
comment:5 by , 17 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at 070ec9559ea245420295836b785be0a7aa92e32e. If there are any changes required for newest Rustc, please make them, Xi. I don't have the newest version on my system yet. Thanks!
Note:
See TracTickets
for help on using tickets.

CVE-2025-4920: This exploit allows for an attacker to read and write out of bounds memory on a JavaScript
promiseobject. Rated critical by Mozilla.CVE-2025-4921: This exploit, like CVE-2025-4920, allows for out of bounds memory read and write through JavaScript, this time by confusing array indexes on a JS object. Also rated critical by Mozilla.
Both of these attacks have been demonstrated at Vancouver Pwn2Own and has displayed that this allows for remote code execution and JS manipulation.
Further reading: https://www.mozilla.org/en-US/security/advisories/mfsa2025-37/
I aim to have this fixed tomorrow. Should get done as soon as possible. Thunderbird should likewise get a release pretty soon with the same fixes. I will be on the lookout for that.