External risk intelligence

Firefox Thunderbird Use-After-Free via Crafted XSLT Data

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-1009

This vulnerability affects web browsers and email clients (Firefox and Thunderbird). These are end-user software applications installed on local systems, not internet-facing servers or gateways. While they access the internet to function, the product role is client-side, making it highly unlikely to be an exposed network service in the context of infrastructure attack surfaces.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability was identified in Mozilla's Firefox and Thunderbird products that could allow an attacker to cause a crash by sending specially crafted data. While the primary concern is confirming relevance and exposure within our environment, this type of issue could potentially lead to further compromise if exploited.

  • Malicious data can crash affected software.
  • Critical flaws can enable further attacks.
  • Confirm relevance and exposure of affected products.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could send specially crafted XSLT data to a vulnerable application. This could lead to a use-after-free condition, potentially causing a crash and enabling further exploitation.

  • No authentication or special access required.
  • Triggered by crafted XSLT data.
  • Risk of exploitable crash.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in Firefox and Thunderbird could allow an attacker to cause a crash by sending specially crafted XSLT data. This crash could potentially be exploited to execute arbitrary code, impacting the integrity and availability of the application.

  • Application crashes and potential code execution.
  • Crafted XSLT data triggers vulnerability.
  • Compromised application integrity and availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Firefox and Thunderbird users. The first practical step is to confirm the presence and reachability of these applications across the organization. Subsequently, identify the accountable owners for these endpoints, whether they are individual users, managed device teams, or a combination, to plan for remediation based on exposure and business criticality.

  • Device and application owners should act.
  • Verify vulnerable software is deployed.
  • Coordinate user-facing updates and patching.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Firefox and Thunderbird in this context?

Firefox is a widely used web browser, and Thunderbird is a popular email client. Both applications are developed by Mozilla and rely on complex rendering engines to process web content and messages. This vulnerability involves how these products handle XSLT (Extensible Stylesheet Language Transformations), which is a language used to format and transform data within the software.

How does the CVE-2025-1009 use-after-free weakness work?

This is a memory management error known as a use-after-free, classified as CWE-416. It occurs when a program continues to use a pointer to a memory location after that memory has been freed or cleared. In CVE-2025-1009, processing specifically crafted XSLT data triggers this mistake, which can lead to unpredictable software crashes or conditions where memory may be manipulated.

What triggers this vulnerability?

The flaw is triggered when the affected software processes specially crafted XSLT data. If the browser or email client does not encounter this specific malicious input, the memory handling error does not occur. Standard, benign XSLT files used in legitimate websites or emails are not the cause of this bug.

Do I need to worry about this if I use these products?

Halo Surface Signal notes that because Firefox and Thunderbird are end-user applications rather than internet-facing infrastructure servers, they are generally not classified as exposed network services. However, because they are used to access the internet, you should ensure these applications are updated on all systems to mitigate risks to individual endpoints.

What is the first step to fix CVE-2025-1009?

Begin by identifying where Firefox and Thunderbird are installed across your environment. Once you have a list of affected devices, coordinate with the device owners or management teams to ensure the software is updated to the fixed versions, such as Firefox 135 or Thunderbird 135. Prioritize updates on systems that frequently access untrusted or high-risk web content.

References