Mozilla Releases Firefox 138 with Major Security Fixes

Mozilla Releases Firefox 138 with Major Security Fixes

Firefox 138 Launches with Enhanced Security and Smarter User Features

Mozilla has unveiled Firefox 138, a release that delivers major under-the-hood security reinforcements alongside improvements that everyday users will appreciate—most notably, a streamlined profile management experience.

This update, pushed live on April 29, 2025, responds to serious vulnerabilities that posed risks ranging from unauthorized system access to process isolation failures. Security teams flagged these issues as critical, prompting Mozilla to act swiftly with targeted fixes designed to prevent potential exploitation.

What’s Been Fixed: Key Security Risks

According to Mozilla’s official security bulletin, four high-severity flaws were addressed in this release, covering both Firefox and its sibling application, Thunderbird. Among the most critical:

  • Privilege Escalation via the Update System (CVE-2025-2817)
    Discovered by Dong-uk Kim (@justlikebono), this flaw allowed lower-privileged processes to interfere with Firefox’s update mechanism—potentially gaining SYSTEM-level access through manipulated file locks.
  • WebGL Memory Corruption on macOS (CVE-2025-4082)
    A vulnerability in shader attribute handling could lead to out-of-bounds memory reads. When exploited in combination with other issues, it had the potential to grant elevated privileges on Mac systems.
  • Cross-Origin Process Confusion (CVE-2025-4083)
    Security expert Nika Layzell uncovered a flaw in how Firefox handled javascript: URIs inside cross-origin iframes. The result: a rare but dangerous loophole that could allow scripts to break out of their sandbox and access unintended resources.
  • Memory Safety Concerns (CVE-2025-4092)
    Mozilla also addressed memory corruption issues found in Firefox 137 and Thunderbird 137. While specifics were limited, Mozilla confirmed that these bugs could be exploited to run unauthorized code.

A Safer, Smarter Browser

With Firefox 138, Mozilla continues to demonstrate its commitment to both user experience and robust security. The update not only neutralizes vulnerabilities before they can be widely exploited but also reinforces the importance of proactive research collaboration between security experts and browser developers.

Summary of Addressed Vulnerabilities in Firefox 138

Vulnerability IDAffected SoftwareType of RiskRequirements for ExploitationSeverity
CVE-2025-2817FirefoxPrivilege escalationRequires local access with the ability to run code as a medium-integrity userHigh
CVE-2025-4082Firefox (macOS only)Memory corruption, potential privilege gainExploitation depends on manipulating specific WebGL shader attributesHigh
CVE-2025-4083FirefoxSandbox escape via process isolation bypassAttacker must control or inject javascript: URIs in cross-origin iframe contextsHigh
CVE-2025-4092Firefox, ThunderbirdMemory corruption, possible code executionRequires user interaction with crafted web content or email to trigger memory bugsHigh

Smarter Browsing with New Profile Management in Firefox 138

Alongside vital security fixes, Firefox 138 debuts a long-requested feature: profile management. This new tool lets users create distinct browsing profiles—ideal for separating work, personal, or testing environments. Each profile maintains its own bookmarks, tabs, passwords, and history, providing greater control and privacy.

While the rollout is gradual, power users can enable it immediately by setting browser.profiles.enabled to true in the about:config panel.

Security Agencies Urge Immediate Updates

The Center for Internet Security (CIS) has labeled the patched vulnerabilities as high risk for enterprise and government systems. Though no active exploitation has been reported, the Cybersecurity and Infrastructure Security Agency (CISA) advises all users to update promptly after appropriate testing.

Firefox 138 is now available for general use, and the Extended Support Release (ESR) builds—versions 115.23 and 128.10—have also been updated with the same critical patches.

More Articles & Posts