CVE-2025-9179

An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*

History

13 Apr 2026, 15:17

Type Values Removed Values Added
Summary (en) An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. (en) An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability was fixed in Firefox 142, Firefox ESR 115.27, Firefox ESR 128.14, Firefox ESR 140.2, Thunderbird 142, Thunderbird 128.14, and Thunderbird 140.2.

03 Nov 2025, 19:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/08/msg00016.html -
  • () https://lists.debian.org/debian-lts-announce/2025/08/msg00018.html -

21 Aug 2025, 18:37

Type Values Removed Values Added
CPE cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:*
First Time Mozilla
Mozilla firefox
Mozilla thunderbird
References () https://bugzilla.mozilla.org/show_bug.cgi?id=1979527 - () https://bugzilla.mozilla.org/show_bug.cgi?id=1979527 - Issue Tracking, Permissions Required
References () https://www.mozilla.org/security/advisories/mfsa2025-64/ - () https://www.mozilla.org/security/advisories/mfsa2025-64/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-65/ - () https://www.mozilla.org/security/advisories/mfsa2025-65/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-66/ - () https://www.mozilla.org/security/advisories/mfsa2025-66/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-67/ - () https://www.mozilla.org/security/advisories/mfsa2025-67/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-70/ - () https://www.mozilla.org/security/advisories/mfsa2025-70/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-71/ - () https://www.mozilla.org/security/advisories/mfsa2025-71/ - Vendor Advisory
References () https://www.mozilla.org/security/advisories/mfsa2025-72/ - () https://www.mozilla.org/security/advisories/mfsa2025-72/ - Vendor Advisory

20 Aug 2025, 16:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-119

20 Aug 2025, 14:39

Type Values Removed Values Added
Summary
  • (es) Un atacante logró corromper la memoria en el proceso GMP, que procesa medios cifrados. Este proceso también está fuertemente protegido, pero sus privilegios son ligeramente diferentes a los del proceso de contenido. Esta vulnerabilidad afecta a Firefox &lt; 142, Firefox ESR &lt; 115.27, Firefox ESR &lt; 128.14, Firefox ESR &lt; 140.2, Thunderbird &lt; 142, Thunderbird &lt; 128.14 y Thunderbird &lt; 140.2.

19 Aug 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-19 21:15

Updated : 2026-04-13 15:17


NVD link : CVE-2025-9179

Mitre link : CVE-2025-9179

CVE.ORG link : CVE-2025-9179


JSON object : View

Products Affected

mozilla

  • firefox
  • thunderbird
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer