Nemeski@lemm.ee to Firefox@fedia.io · 17 days agoFirefox 138.0.4 Release Noteswww.mozilla.orgexternal-linkmessage-square2fedilinkarrow-up127arrow-down10cross-posted to: [email protected]
arrow-up127arrow-down1external-linkFirefox 138.0.4 Release Noteswww.mozilla.orgNemeski@lemm.ee to Firefox@fedia.io · 17 days agomessage-square2fedilinkcross-posted to: [email protected]
minus-squarenesc@lemmy.cafelinkfedilinkarrow-up6·17 days agoFixed: https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/#CVE-2025-4920 An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object. https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/#CVE-2025-4921 An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes.
minus-squaremonogram@feddit.nllinkfedilinkarrow-up6·17 days agoAnother reason the rust rewrite would have helped Firefox
Fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/#CVE-2025-4920
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object.
https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/#CVE-2025-4921
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes.
Another reason the rust rewrite would have helped Firefox