External risk intelligence

JavaScript Promise Out-of-Bounds Read Write Vulnerability in Firefox and Thunderbird

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-4918

This vulnerability affects client-side software (web browsers and email clients). These applications are user-interactive tools, not internet-facing services or gateways, and are typically not exposed to the public internet as network-reachable attack surfaces.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Mozilla's Firefox and Thunderbird software, stemming from an out-of-bounds read or write error within JavaScript's Promise object. This flaw could potentially allow for significant compromise of system integrity and confidentiality, affecting how these widely used applications handle data.

  • Flaw allows unauthorized reading or writing of data.
  • Matters for users interacting with affected browsers.
  • Confirm relevance and exposure of this software.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted web page or email that triggers an out-of-bounds read or write condition within the JavaScript engine of affected software. This could potentially allow an attacker to compromise the confidentiality, integrity, and availability of the affected application.

  • No special access needed.
  • Triggered by interacting with malicious content.
  • Allows reading, writing, and execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could exploit this vulnerability to read or write data outside the intended boundaries of a JavaScript `Promise` object. This could affect the integrity and availability of the application's processes.

  • Application memory state.
  • Remote code execution is possible.
  • Application disruption.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-World Ownership

The primary teams responsible for addressing this vulnerability are likely those managing endpoint security and application deployment, such as IT Operations, Security Operations, and potentially end-user support teams. The initial action should focus on identifying all instances of the affected software, determining their reachability and business criticality, and then engaging the appropriate application or system owners to plan and execute remediation.

  • Identify affected software and owners.
  • Verify exposure and business impact.
  • Plan and coordinate remediation activities.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Firefox and Thunderbird in the context of CVE-2025-4918?

Firefox is a web browser used for navigating the internet, while Thunderbird is a dedicated email client used for managing communications. Both applications rely on a shared JavaScript engine to interpret web-based code, which is the specific component affected by this vulnerability.

What does out-of-bounds read or write mean for a JavaScript Promise?

This vulnerability involves memory safety weaknesses categorized as CWE-125 and CWE-787. Normally, a Promise manages data within strict memory limits. This bug allows the engine to access or modify data outside those intended boundaries, which can disrupt the program's memory state or potentially allow unauthorized data manipulation.

How is this vulnerability triggered?

An attacker triggers the flaw by directing a user to load a specially crafted web page or by sending a malicious email. The bug is not triggered by simply having the software installed or idle; it requires the application's engine to process the malicious JavaScript content.

Do I need to worry about this if I use these applications?

Halo Surface Signal notes that this vulnerability affects client-side software rather than internet-facing infrastructure. Because you interact with these tools directly, your primary risk comes from navigating to untrusted websites or opening suspicious emails rather than the software being reached by external network attacks.

When should I update my software to address CVE-2025-4918?

You should apply the provided updates immediately. Since this bug allows for significant compromise, moving to the corrected versions—such as Firefox 138.0.4 or the corresponding Thunderbird releases—is the necessary step to patch the memory handling error.

References