Firefox 138.0.4 Release Notes
Firefox 138.0.4 Release Notes
2
comments
Fixed:
https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/#CVE-2025-4920
An attacker was able to perform an out-of-bounds read or write on a JavaScript Promise object.
https://www.mozilla.org/en-US/security/advisories/mfsa2025-36/#CVE-2025-4921
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes.
6 0 ReplyAnother reason the rust rewrite would have helped Firefox
6 0 Reply