Critical Firefox 0-Day Exploits Let Hackers Run Malicious Code

Critical Firefox 0-Day Exploits Let Hackers Run Malicious Code

Urgent Firefox Update Fixes Two Critical Security Bugs Allowing Remote Code Execution

Mozilla has issued an urgent patch for Firefox following the discovery of two high-risk vulnerabilities that pose a serious threat to user safety. These flaws, found deep in the browser’s JavaScript engine, could allow cybercriminals to seize control of a system with minimal user interaction.

Users Urged to Update Immediately

The affected Firefox versions are vulnerable to code execution exploits triggered simply by visiting a malicious webpage. Security professionals stress that the update should be applied without delay to prevent potential breaches.

Zero-Day Flaws Allow Remote Attacks

The weaknesses, catalogued as CVE-2025-4918 and CVE-2025-4919, were identified through coordinated research efforts by Trend Micro’s Zero Day Initiative and have been flagged as critical by Mozilla. Exploiting either flaw could enable attackers to run arbitrary code on a victim’s device.

  • CVE-2025-4918 centers on a memory handling error involving JavaScript Promise objects. By manipulating how Firefox reads or writes data in memory, attackers can breach system defenses.
  • CVE-2025-4919 involves mishandling of array index calculations, which also opens the door for unauthorized memory access and code execution.

These bugs were uncovered by cybersecurity experts Edouard Bochin and Tao Yan (Palo Alto Networks) and Manfred Paul, respectively.

Impact and Risk

Attackers need only lure users to a specially crafted website to initiate the exploit, making this an especially dangerous pair of bugs. Mozilla’s advisory emphasizes that these flaws are being taken seriously due to the low barrier to exploitation and high potential for harm.

Recommendation

All Firefox users—individuals and organizations alike—should upgrade to the latest version immediately to ensure their systems are protected.

Security Vulnerability Overview

IdentifierImpacted VersionsPotential RiskConditions for ExploitationSeverity Score (CVSS v3.1)
CVE-2025-4918CVE-2025-4919– Firefox versions prior to 138.0.4- Firefox ESR prior to 128.10.1- Firefox ESR prior to 115.23.1Remote Code ExecutionRequires the user to visit a specially designed malicious webpage8.8 (High)

Summary:
These critical vulnerabilities in Firefox could be exploited to execute unauthorized code on affected systems. Successful attacks depend on users being tricked into accessing a malicious site, highlighting the need for immediate browser updates.

Who’s at Risk? Firefox Users Urged to Patch Critical Security Holes

Multiple versions of Mozilla Firefox—including mainstream and Extended Support Releases—are exposed to serious vulnerabilities that could allow attackers to execute malicious code remotely. The affected versions include:

  • Firefox versions before 138.0.4
  • Firefox ESR releases prior to 128.10.1 and 115.23.1

Security intelligence firm Cybersecurity Help has confirmed that the risk window stretches from Firefox 110.0 through 138.0.3, and Firefox ESR builds from 102.0 up to 128.10.0.

High-Risk Alert: CVSS Score 8.8

These vulnerabilities carry a Common Vulnerability Scoring System (CVSS) rating of 8.8, placing them in the high-risk category. The flaws represent a real-world threat, especially if users are lured to compromised or maliciously crafted websites.

Vulnerabilities Uncovered in the Wild

The flaws were publicly demonstrated at the Pwn2Own 2025 security contest—highlighting just how feasible these attacks are for skilled adversaries. Mozilla’s security team responded swiftly, issuing emergency updates to contain the threat.

Immediate Action Required: Update Now

To safeguard your system:

  • Upgrade to Firefox 138.0.4
  • ESR users: move to 128.10.1 or 115.23.1, depending on your deployment path

To apply the fix, go to the Firefox menu, select “Help” → “About Firefox”. On macOS, click “About Firefox” directly from the menu.

Stay Ahead of Evolving Browser Threats

With attackers continually refining browser-based exploitation techniques, keeping your browser updated is your front line of defense. These latest patches close critical gaps that could otherwise be used to breach your system or compromise sensitive data.

More Articles & Posts