CVE-2025-0240
Executive Summary
CVE-2025-0240: Parsing a JavaScript module as JSON can trigger cross‑compartment access leading to a use‑after‑free in Firefox and Thunderbird. Fixed in Firefox 134/ESR 128.6 and Thunderbird 134/ESR 128.6. No current CISA KEV listing.
Authoritative CVE Metadata - CVSS Base Score: 4.0 (MEDIUM) - Published: 2025-01-07T16:15:38.663 - Last Modified: 2026-10-05T15:10:00.590
Original Description: Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.
"What lies behind us and what lies before us are tiny matters compared to what lies within us."
— Walt Emerson
Source: NVD