External risk intelligence

Firefox and Thunderbird WASM Branch Table Incorrect Address Calculation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-8028

The vulnerability affects client-side software (web browsers and email clients). These applications run locally on end-user devices and are not designed as internet-facing services, gateways, or infrastructure that would provide a public network-reachable attack surface in typical deployment scenarios.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A recent security vulnerability has been identified in certain versions of Firefox and Thunderbird that could allow for incorrect computation of branch addresses within WebAssembly code on arm64 architecture. While the primary concern is confirming relevance and exposure, this issue has been addressed in updated versions of the affected software.

  • Flaw in WebAssembly code processing.
  • Affects client-side applications like browsers.
  • Confirm relevance and exposure of affected software.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by directing a user to a malicious web page or sending a specially crafted email. The attack targets the WebAssembly (WASM) execution engine within the affected browser or email client. When processing a `br_table` instruction with numerous entries, the engine may miscalculate branch addresses due to label distance, potentially leading to code execution.

  • No authentication or user interaction needed.
  • Triggered by processing a complex WASM instruction.
  • Enables code execution for significant impact.

Live Threat

Current exploitation, exposure, and threat context

A malformed WebAssembly instruction in Firefox or Thunderbird could allow an attacker to disrupt normal program execution, potentially leading to unpredictable behavior. This could occur when processing certain WebAssembly modules, especially on arm64 architectures.

  • WebAssembly execution state.
  • Malicious WebAssembly module execution.
  • Unpredictable service behavior.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects Mozilla Firefox and Thunderbird, impacting users on arm64 architectures. Real-world ownership likely falls to endpoint security teams and potentially application support teams responsible for managing user-facing software. The first practical step involves identifying all deployed instances of the affected software across the organization, assessing their potential reachability by malicious actors (though the context suggests client-side impact), and confirming the business criticality of affected endpoints. Once ownership is clarified, a risk-based remediation plan, considering user impact and available maintenance windows, can be developed.

  • Endpoint security and application support teams.
  • Verify all affected software instances exist.
  • Plan targeted updates or user guidance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the software affected by CVE-2025-8028?

This vulnerability impacts Mozilla Firefox and Thunderbird. These are widely used client-side applications: Firefox functions as a web browser for accessing internet content, while Thunderbird serves as a cross-platform email, news feed, and chat client. The flaw specifically pertains to how these programs handle WebAssembly (WASM) code when running on devices powered by arm64 processor architectures, such as modern Macs with Apple Silicon or various ARM-based systems.

What does this WASM vulnerability mean?

This flaw is classified as CWE-1332, which involves improper handling of length or distance calculations. In this case, the browser's engine miscalculates the destination address for a specific WebAssembly instruction called 'br_table' when it contains a very high number of entries. Because the label is physically too far from the instruction, the calculation results in an incorrect branch address, which can cause the program to behave unpredictably or run unauthorized code.

How is this branch address bug triggered?

An attacker triggers this by enticing a user to load a specially crafted WebAssembly module. This typically happens through a malicious webpage or a compromised email. The bug specifically requires the 'br_table' instruction to have a large number of entries on an arm64 system. Normal, everyday WASM code that does not utilize these specific, high-density branching structures will not trigger this memory calculation error.

Do I need to worry about this on my servers?

According to Halo Surface Signal, this is very unlikely to be an infrastructure risk. Because Firefox and Thunderbird are client-side applications designed to run locally on end-user devices, they do not present the type of public, network-accessible attack surface found in gateways or backend servers. While the impact on an individual user's device is high, it is not an internet-facing service vulnerability that would typically expose your internal network directly.

When should I update Firefox or Thunderbird?

You should prioritize updating these applications immediately. The first step is to identify all endpoints in your organization running older versions of Firefox or Thunderbird, specifically looking for those on arm64 hardware. Once identified, apply the patches released by Mozilla—such as version 141 or the corresponding ESR releases—to replace the vulnerable WebAssembly engine with one that correctly handles complex branch address calculations.

References