Firefox 138 Launches with Enhanced Security and Smarter User Features
Mozilla has unveiled Firefox 138, a release that delivers major under-the-hood security reinforcements alongside improvements that everyday users will appreciate—most notably, a streamlined profile management experience.
This update, pushed live on April 29, 2025, responds to serious vulnerabilities that posed risks ranging from unauthorized system access to process isolation failures. Security teams flagged these issues as critical, prompting Mozilla to act swiftly with targeted fixes designed to prevent potential exploitation.
What’s Been Fixed: Key Security Risks
According to Mozilla’s official security bulletin, four high-severity flaws were addressed in this release, covering both Firefox and its sibling application, Thunderbird. Among the most critical:
- Privilege Escalation via the Update System (CVE-2025-2817)
Discovered by Dong-uk Kim (@justlikebono), this flaw allowed lower-privileged processes to interfere with Firefox’s update mechanism—potentially gaining SYSTEM-level access through manipulated file locks. - WebGL Memory Corruption on macOS (CVE-2025-4082)
A vulnerability in shader attribute handling could lead to out-of-bounds memory reads. When exploited in combination with other issues, it had the potential to grant elevated privileges on Mac systems. - Cross-Origin Process Confusion (CVE-2025-4083)
Security expert Nika Layzell uncovered a flaw in how Firefox handledjavascript:URIs inside cross-origin iframes. The result: a rare but dangerous loophole that could allow scripts to break out of their sandbox and access unintended resources. - Memory Safety Concerns (CVE-2025-4092)
Mozilla also addressed memory corruption issues found in Firefox 137 and Thunderbird 137. While specifics were limited, Mozilla confirmed that these bugs could be exploited to run unauthorized code.
A Safer, Smarter Browser
With Firefox 138, Mozilla continues to demonstrate its commitment to both user experience and robust security. The update not only neutralizes vulnerabilities before they can be widely exploited but also reinforces the importance of proactive research collaboration between security experts and browser developers.
Summary of Addressed Vulnerabilities in Firefox 138
| Vulnerability ID | Affected Software | Type of Risk | Requirements for Exploitation | Severity |
|---|---|---|---|---|
| CVE-2025-2817 | Firefox | Privilege escalation | Requires local access with the ability to run code as a medium-integrity user | High |
| CVE-2025-4082 | Firefox (macOS only) | Memory corruption, potential privilege gain | Exploitation depends on manipulating specific WebGL shader attributes | High |
| CVE-2025-4083 | Firefox | Sandbox escape via process isolation bypass | Attacker must control or inject javascript: URIs in cross-origin iframe contexts | High |
| CVE-2025-4092 | Firefox, Thunderbird | Memory corruption, possible code execution | Requires user interaction with crafted web content or email to trigger memory bugs | High |
Smarter Browsing with New Profile Management in Firefox 138
Alongside vital security fixes, Firefox 138 debuts a long-requested feature: profile management. This new tool lets users create distinct browsing profiles—ideal for separating work, personal, or testing environments. Each profile maintains its own bookmarks, tabs, passwords, and history, providing greater control and privacy.
While the rollout is gradual, power users can enable it immediately by setting browser.profiles.enabled to true in the about:config panel.
Security Agencies Urge Immediate Updates
The Center for Internet Security (CIS) has labeled the patched vulnerabilities as high risk for enterprise and government systems. Though no active exploitation has been reported, the Cybersecurity and Infrastructure Security Agency (CISA) advises all users to update promptly after appropriate testing.
Firefox 138 is now available for general use, and the Extended Support Release (ESR) builds—versions 115.23 and 128.10—have also been updated with the same critical patches.




