Mozilla Foundation Security Advisory 2025-25

Security vulnerability fixed in Firefox 137.0.2

Announced
April 15, 2025
Impact
high
Products
Firefox
Fixed in
  • Firefox 137.0.2

#CVE-2025-3608: Race condition in nsHttpTransaction could lead to memory corruption

Reporter
The Mozilla Fuzzing Team
Impact
high
Description

A race condition existed in nsHttpTransaction that could have been exploited to cause memory corruption, potentially leading to an exploitable condition.

References