CVE-2025-4918
published 2025-05-17CVE-2025-4918: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR…
PriorityP356critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
8.95%
94.7th percentile
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | firefox | < firefox 138.0.4-1 (sid) | firefox 138.0.4-1 (sid) |
| debian | firefox-esr | < firefox 138.0.4-1 (sid) | firefox 138.0.4-1 (sid) |
| debian | thunderbird | < firefox 138.0.4-1 (sid) | firefox 138.0.4-1 (sid) |
| mozilla | firefox | < 115.23.1 | 115.23.1 |
| mozilla | firefox | < 138.0.4 | 138.0.4 |
| mozilla | firefox | — | — |
| mozilla | firefox | >= 116.0 < 128.10.1 | 128.10.1 |
| mozilla | thunderbird | < 128.10.2 | 128.10.2 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1~deb11u1 | 1:128.11.0esr-1~deb11u1 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1~deb12u1 | 1:128.11.0esr-1~deb12u1 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1 | 1:128.11.0esr-1 |
| mozilla | thunderbird | >= 0 < 1:128.11.0esr-1 | 1:128.11.0esr-1 |
| mozilla | thunderbird | >= 138.0 < 138.0.2 | 138.0.2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2025-07-22
CVE-2025-4083 Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
Multiple security issues were discovered in Thunderbird. If a user were
tricked into opening a specially crafted website in a browsing context, an
attacker could potentially exploit these to cause a denial of service,
obtain sensitive information, bypass security restrictions, cross-site
tracing, or execute arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart thunderbird to
make all the necessary changes.
Red Hat
firefox: thunderbird: Out-of-bounds access when resolving Promise objects
vendor_redhat·2025-05-17·CVSS 9.8
CVE-2025-4918 [CRITICAL] CWE-787 firefox: thunderbird: Out-of-bounds access when resolving Promise objects
firefox: thunderbird: Out-of-bounds access when resolving Promise objects
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object.
Statement: Red Hat Product Security rates the severity of this flaw as Important due to the requirement of user interaction.
Mitigation: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability,
Debian
CVE-2025-4918: firefox - An attacker was able to perform an out-of-bounds read or write on a JavaScript `...
vendor_debian·2025·CVSS 9.8
CVE-2025-4918 [CRITICAL] CVE-2025-4918: firefox - An attacker was able to perform an out-of-bounds read or write on a JavaScript `...
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
Scope: local
sid: resolved (fixed in 138.0.4-1)
Mozilla
Mozilla Foundation Security Advisory 2025-36: CVE-2025-4918
vendor_mozilla·CVSS 9.8
CVE-2025-4918 [CRITICAL] Mozilla Foundation Security Advisory 2025-36: CVE-2025-4918
Mozilla Foundation Security Advisory 2025-36
CVE: CVE-2025-4918
Product: Firefox
Impact: critical
Fixed in: Firefox 138.0.4
Mozilla
Mozilla Foundation Security Advisory 2025-37: CVE-2025-4918
vendor_mozilla·CVSS 9.8
CVE-2025-4918 [CRITICAL] Mozilla Foundation Security Advisory 2025-37: CVE-2025-4918
Mozilla Foundation Security Advisory 2025-37
CVE: CVE-2025-4918
Product: Firefox ESR
Impact: critical
Fixed in: Firefox ESR 128.10.1
Mozilla
Mozilla Foundation Security Advisory 2025-41: CVE-2025-4918
vendor_mozilla·CVSS 9.8
CVE-2025-4918 [CRITICAL] Mozilla Foundation Security Advisory 2025-41: CVE-2025-4918
Mozilla Foundation Security Advisory 2025-41
CVE: CVE-2025-4918
Product: Thunderbird
Impact: critical
Fixed in: Thunderbird 138.0.2
Mozilla
Mozilla Foundation Security Advisory 2025-38: CVE-2025-4918
vendor_mozilla·CVSS 9.8
CVE-2025-4918 [CRITICAL] Mozilla Foundation Security Advisory 2025-38: CVE-2025-4918
Mozilla Foundation Security Advisory 2025-38
CVE: CVE-2025-4918
Product: Firefox ESR
Impact: critical
Fixed in: Firefox ESR 115.23.1
Mozilla
Mozilla Foundation Security Advisory 2025-40: CVE-2025-4918
vendor_mozilla·CVSS 9.8
CVE-2025-4918 [CRITICAL] Mozilla Foundation Security Advisory 2025-40: CVE-2025-4918
Mozilla Foundation Security Advisory 2025-40
CVE: CVE-2025-4918
Product: Thunderbird
Impact: critical
Fixed in: Thunderbird 128.10.2
GHSA
GHSA-fhgm-mxgh-gfpj: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object
ghsa_unreviewed·2025-05-18
CVE-2025-4918 [HIGH] CWE-125 GHSA-fhgm-mxgh-gfpj: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox ESR < 115.23.1.
OSV
CVE-2025-4918: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object
osv·2025-05-17·CVSS 9.8
CVE-2025-4918 [CRITICAL] CVE-2025-4918: An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object
An attacker was able to perform an out-of-bounds read or write on a JavaScript `Promise` object. This vulnerability affects Firefox < 138.0.4, Firefox ESR < 128.10.1, Firefox ESR < 115.23.1, Thunderbird < 128.10.2, and Thunderbird < 138.0.2.
No detection rules found.
No public exploits indexed.
Checkpoint
26th May – Threat Intelligence Report
blogs_checkpoint·2025-05-26
CVE-2025-4918 26th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 26th May, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Cellcom, a Wisconsin-based wireless provider, has been impacted by a cyberattack that resulted in widespread outages of voice and SMS services beginning on May 14, 2025. The incident disrupted communication for customers across Wisconsin and Upper Michigan, leaving them unable to make phone calls or send text messages. No threat
Bleepingcomputer
Mozilla fixes Firefox zero-days exploited at hacking contest
blogs_bleepingcomputer·2025-05-19·CVSS 9.8
CVE-2025-4918 [CRITICAL] Mozilla fixes Firefox zero-days exploited at hacking contest
## Mozilla fixes Firefox zero-days exploited at hacking contest
## Bill Toulas
Mozilla released emergency security updates to address two Firefox zero-day vulnerabilities demonstrated in the recent Pwn2Own Berlin 2025 hacking competition.
The fixes, which include the Firefox on Desktop and Android and two Extended Support Releases (ESR), came mere hours after the conclusion of Pwn2Own, on Saturday, where the second vulnerability was demonstrated.
The first flaw, tracked under CVE-2025-4918 , is an out-of-bounds read/write issue in the JavaScript engine when resolving Promise objects.
The flaw was demonstrated during Day 2 of the competition by Palo Alto Networks security researchers Edouard Bochin and Tao Yan, who earned $50,000 for their discovery.
The second flaw, CVE-2025-4919 , a
Bleepingcomputer
Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin
blogs_bleepingcomputer·2025-05-19
Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin
## Hackers earn $1,078,750 for 28 zero-days at Pwn2Own Berlin
## Sergiu Gatlan
The Pwn2Own Berlin 2025 hacking competition has concluded, with security researchers earning $1,078,750 after exploiting 29 zero-day vulnerabilities and encountering some bug collisions.
Throughout the contest, they targeted enterprise technologies in the AI, web browser, virtualization, local privilege escalation, servers, enterprise applications, cloud-native/container, and automotive categories.
According to Pwn2Own's rules , all targeted devices had all security updates installed and ran the latest operating system versions.
While Tesla also provided two 2025 Tesla Model Y and 2024 Tesla Model 3 bench-top units, security researchers who joined the contest haven't registered any attempts in this category
https://bugzilla.mozilla.org/show_bug.cgi?id=1966612https://www.mozilla.org/security/advisories/mfsa2025-36/https://www.mozilla.org/security/advisories/mfsa2025-37/https://www.mozilla.org/security/advisories/mfsa2025-38/https://www.mozilla.org/security/advisories/mfsa2025-40/https://www.mozilla.org/security/advisories/mfsa2025-41/https://lists.debian.org/debian-lts-announce/2025/05/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2025/05/msg00046.htmlhttps://www.vicarius.io/vsociety/posts/cve-2025-4918-detect-firefox-out-of-bounds-writehttps://www.vicarius.io/vsociety/posts/cve-2025-4918-mitigate-firefox-out-of-bounds-write
2025-05-17
Published