CVE advisoryCRITICAL
CVE-2025-4918
JavaScript Promise Out-of-Bounds Read Write Vulnerability in Firefox and Thunderbird
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
A vulnerability in JavaScript's Promise object within Mozilla's Firefox and Thunderbird allows for out-of-bounds reads or writes. This could impact data integrity and availability if triggered by malicious content. The affected technology is client-side software, meaning user interaction is typically required.