An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2.
Metrics
Affected Vendors & Products
References
History
Fri, 22 Aug 2025 00:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | thunderbird: firefox: Sandbox escape due to invalid pointer in the Audio/Video: GMP component | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Thu, 21 Aug 2025 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:-:*:*:* cpe:2.3:a:mozilla:thunderbird:*:*:*:*:esr:*:*:* |
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mozilla
Mozilla firefox Mozilla firefox Esr Mozilla thunderbird |
|
Vendors & Products |
Mozilla
Mozilla firefox Mozilla firefox Esr Mozilla thunderbird |
Wed, 20 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-119 | |
Metrics |
cvssV3_1
|
Tue, 19 Aug 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed, but represents slightly different privileges from the content process. This vulnerability affects Firefox < 142, Firefox ESR < 115.27, Firefox ESR < 128.14, Firefox ESR < 140.2, Thunderbird < 142, Thunderbird < 128.14, and Thunderbird < 140.2. | |
References |
|
|

Status: PUBLISHED
Assigner: mozilla
Published: 2025-08-19T20:33:53.949Z
Updated: 2025-08-20T15:18:57.429Z
Reserved: 2025-08-19T15:55:37.418Z
Link: CVE-2025-9179

Updated: 2025-08-20T14:06:17.281Z

Status : Analyzed
Published: 2025-08-19T21:15:30.247
Modified: 2025-08-21T18:37:45.553
Link: CVE-2025-9179
