Description
Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.
Published: 2025-10-14
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free leading to memory corruption
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free occurring in the MediaTrackGraphImpl::GetInstance() actor of Mozilla’s media handling stack. Premature deallocation followed by subsequent access can corrupt memory, which for a process with sufficient privileges could permit an attacker to execute arbitrary code or crash the application. The CVSS score of 9.8 reflects the severe potential impact, although the advisory itself does not detail a confirmed execution path.

Affected Systems

All releases of Mozilla Firefox and Firefox ESR before version 144 and 140.4 respectively, and all releases of Mozilla Thunderbird and Thunderbird ESR before version 144 and 140.4 respectively, are affected. The fix is incorporated in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird ESR 140.4.

Risk and Exploitability

The high CVSS score indicates a serious outcome if the flaw is exploited, while the EPSS score of < 1% suggests that exploit attempts are currently rare. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, but the combination of severity and low exploitation probability still warrants focused remediation to prevent future attacks that could leverage similar exploitation techniques.

Generated by OpenCVE AI on April 20, 2026 at 19:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mozilla Firefox to version 144 or newer, or Firefox ESR 140.4 or newer.
  • Upgrade Mozilla Thunderbird to version 144 or newer, or Thunderbird ESR 140.4 or newer.
  • If an immediate update is unavailable, restrict or disable playback of external media content from untrusted origins and apply application policy settings that limit the execution of the media processing components until the patch is installed.

Generated by OpenCVE AI on April 20, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4335-1 firefox-esr security update
Debian DLA Debian DLA DLA-4351-1 thunderbird security update
Debian DSA Debian DSA DSA-6025-1 firefox-esr security update
Debian DSA Debian DSA DSA-6040-1 thunderbird security update
Ubuntu USN Ubuntu USN USN-7991-1 Thunderbird vulnerabilities
History

Mon, 13 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4. Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Thunderbird 144, and Thunderbird 140.4.

Mon, 03 Nov 2025 18:30:00 +0000


Thu, 30 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Title thunderbird: firefox: Use-after-free in MediaTrackGraphImpl::GetInstance() Use-after-free in MediaTrackGraphImpl::GetInstance()

Mon, 20 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla firefox Esr
Vendors & Products Mozilla firefox Esr

Fri, 17 Oct 2025 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Mozilla
Mozilla firefox
Mozilla thunderbird
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*
Vendors & Products Mozilla
Mozilla firefox
Mozilla thunderbird

Wed, 15 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 15 Oct 2025 12:30:00 +0000

Type Values Removed Values Added
Title thunderbird: firefox: Use-after-free in MediaTrackGraphImpl::GetInstance()
Weaknesses CWE-416
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Tue, 14 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Description Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144, Firefox ESR < 140.4, Thunderbird < 144, and Thunderbird < 140.4.
References

Subscriptions

Mozilla Firefox Firefox Esr Thunderbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mozilla

Published:

Updated: 2026-04-13T14:29:38.732Z

Reserved: 2025-10-13T19:49:57.420Z

Link: CVE-2025-11708

cve-icon Vulnrichment

Updated: 2025-11-03T17:31:44.090Z

cve-icon NVD

Status : Modified

Published: 2025-10-14T13:15:36.970

Modified: 2026-04-13T15:16:39.173

Link: CVE-2025-11708

cve-icon Redhat

Severity : Important

Publid Date: 2025-10-14T12:27:35Z

Links: CVE-2025-11708 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T19:15:15Z

Weaknesses